VARIoT news about IoT security

Trust: 4.0

Fetched: Jan. 15, 2025, 9:44 a.m., Published: -
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 3.0

Fetched: Jan. 15, 2025, 9:42 a.m., Published: Jan. 15, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2025-21323, CVE-2025-21382, CVE-2025-21219, CVE-2025-21250, CVE-2025-21354, CVE-2025-21339, CVE-2025-21246, CVE-2025-21389, CVE-2025-21335, CVE-2025-21341, CVE-2025-21311, CVE-2025-21282, CVE-2025-21171, CVE-2025-21403, CVE-2025-21321, CVE-2025-21378, CVE-2025-21186, CVE-2025-21328, CVE-2025-21317, CVE-2025-21297, CVE-2025-21268, CVE-2025-21224, CVE-2025-21225, CVE-2025-21329, CVE-2025-21275, CVE-2025-21298, CVE-2025-21213, CVE-2025-21227, CVE-2025-21261, CVE-2025-21220, CVE-2025-21292, CVE-2025-21245, CVE-2025-21312, CVE-2025-21263, CVE-2025-21249, CVE-2025-21189, CVE-2025-21319, CVE-2025-21301, CVE-2025-21362, CVE-2025-21226, CVE-2025-21345, CVE-2025-21305, CVE-2025-21332, CVE-2025-21236, CVE-2025-21252, CVE-2025-21306, CVE-2025-21294, CVE-2025-21326, CVE-2025-21302, CVE-2025-21333, CVE-2025-21417, CVE-2025-21234, CVE-2025-21320, CVE-2025-21215, CVE-2025-21265, CVE-2025-21374, CVE-2025-21280, CVE-2025-21411, CVE-2025-21278, CVE-2025-21385, CVE-2025-21360, CVE-2025-21277, CVE-2025-21365, CVE-2025-21274, CVE-2025-21202, CVE-2025-21357, CVE-2025-21336, CVE-2025-21284, CVE-2025-21230, CVE-2025-21291, CVE-2025-21348, CVE-2025-21293, CVE-2025-21223, CVE-2025-21327, CVE-2025-21276, CVE-2025-21187, CVE-2025-21309, CVE-2025-21318, CVE-2025-21314, CVE-2025-21270, CVE-2025-21340, CVE-2025-21218, CVE-2025-21233, CVE-2025-21235, CVE-2025-21243, CVE-2025-21361, CVE-2025-21289, CVE-2025-21172, CVE-2025-21266, CVE-2025-21409, CVE-2025-21258, CVE-2025-21331, CVE-2025-21330, CVE-2025-21413, CVE-2025-21214, CVE-2025-21244, CVE-2025-21315, CVE-2025-21393, CVE-2025-21346, CVE-2025-21307, CVE-2025-21229, CVE-2025-21239, CVE-2025-21231, CVE-2025-21338, CVE-2025-21364, CVE-2025-21240, CVE-2025-21242, CVE-2025-21356, CVE-2025-21299, CVE-2025-21248, CVE-2025-21237, CVE-2025-21324, CVE-2025-21173, CVE-2025-21288, CVE-2025-21343, CVE-2025-21228, CVE-2025-21210, CVE-2025-21281, CVE-2025-21402, CVE-2025-21176, CVE-2025-21313, CVE-2025-21366, CVE-2025-21207, CVE-2025-21308, CVE-2025-21273, CVE-2025-21178, CVE-2025-21296, CVE-2025-21256, CVE-2025-21304, CVE-2025-21232, CVE-2025-21405, CVE-2025-21251, CVE-2025-21285, CVE-2025-21363, CVE-2025-21395, CVE-2025-21211, CVE-2025-21303, CVE-2025-21300, CVE-2025-21286, CVE-2025-21257, CVE-2025-21271, CVE-2025-21295, CVE-2025-21310, CVE-2025-21334, CVE-2025-21372, CVE-2025-21290, CVE-2025-21255, CVE-2024-7344, CVE-2025-21344, CVE-2025-21287, CVE-2024-50338, CVE-2025-21241, CVE-2025-21370, CVE-2025-21238, CVE-2025-21269, CVE-2025-21193, CVE-2025-21316, CVE-2025-21217, CVE-2025-21272, CVE-2025-21260, CVE-2025-21380

Trust: 3.5

Fetched: Jan. 15, 2025, 9:42 a.m., Published: Jan. 14, 2025, 12:18 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2025-0282, CVE-2025-0283

Trust: 3.25

Fetched: Jan. 15, 2025, 9:41 a.m., Published: Jan. 14, 2025, 8 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2024-55591

Trust: 4.75

Fetched: Jan. 15, 2025, 9:34 a.m., Published: Jan. 14, 2025, 8:40 p.m.
Vulnerabilities: denial of service, code execution, information disclosure...
Affected productsExternal IDs
db: NVD ids: CVE-2025-21219, CVE-2025-21210, CVE-2025-21335, CVE-2025-21308, CVE-2025-21311, CVE-2025-21333, CVE-2025-21315, CVE-2025-21307, CVE-2025-21334, CVE-2025-21328, CVE-2025-21365, CVE-2025-21297, CVE-2025-21268, CVE-2025-21224, CVE-2025-21329, CVE-2025-21298, CVE-2025-21292, CVE-2025-21364, CVE-2025-21309, CVE-2025-21269, CVE-2025-21314, CVE-2025-21299, CVE-2025-21189

Trust: 3.0

Fetched: Jan. 15, 2025, 9:33 a.m., Published: Jan. 14, 2025, 9:25 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-55591

Trust: 5.0

Fetched: Jan. 15, 2025, 9:33 a.m., Published: Jan. 5, 2025, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2024-7322

Trust: 3.75

Fetched: Jan. 15, 2025, 9:32 a.m., Published: Jan. 15, 2025, 12:14 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-21308, CVE-2025-21334, CVE-2025-21333, CVE-2024-38014, CVE-2020-16885, CVE-2025-21335, CVE-2025-21307, CVE-2025-21275, CVE-2025-21298

Trust: 5.25

Fetched: Jan. 15, 2025, 9:32 a.m., Published: Jan. 14, 2025, 8:12 a.m.
Vulnerabilities: directory traversal, denial of service, code execution...
Affected productsExternal IDs
vendor: mitel model: micollab
vendor: palo model: firewall
vendor: palo model: networks
vendor: palo model: ssl vpn
vendor: palo model: pan-os
db: NVD ids: CVE-2024-53677, CVE-2023-50164, CVE-2023-28461, CVE-2024-49138, CVE-2024-35286, CVE-2024-35250, CVE-2024-3393, CVE-2024-11667, CVE-2024-41713

Trust: 3.0

Fetched: Jan. 15, 2025, 9:30 a.m., Published: Jan. 15, 2025, 9:30 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: fortigate model: fortios

Trust: 4.75

Fetched: Jan. 15, 2025, 9:30 a.m., Published: Jan. 14, 2025, midnight
Vulnerabilities: buffer overflow
Affected productsExternal IDs
vendor: trend model: security
db: NVD ids: CVE-2023-46805, CVE-2025-0282, CVE-2024-21887

Trust: 3.0

Fetched: Jan. 15, 2025, 9:22 a.m., Published: Jan. 20, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: realtek model: realtek sdk

Trust: 3.25

Fetched: Jan. 15, 2025, 9:21 a.m., Published: Jan. 15, 2025, 3:42 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone

Trust: 4.25

Fetched: Jan. 15, 2025, 9:21 a.m., Published: Jan. 5, 2025, midnight
Vulnerabilities: sql injection, default credentials, cross-site scripting
Affected productsExternal IDs
vendor: wireshark model: wireshark

Trust: 4.5

Fetched: Jan. 15, 2025, 9:19 a.m., Published: Jan. 14, 2025, midnight
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: sonicwall model: ssl vpn
vendor: sonicwall model: sonicos
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-40766, CVE-2024-55591

Trust: 5.75

Fetched: Jan. 14, 2025, 10 a.m., Published: Dec. 30, 2024, 7:44 a.m.
Vulnerabilities: improper access control
Affected productsExternal IDs
vendor: d-link model: router
vendor: d-link model: dir-823g
db: NVD ids: CVE-2024-13030

Trust: 4.25

Fetched: Jan. 14, 2025, 9:59 a.m., Published: Jan. 14, 7170, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: canonical model: ubuntu
db: NVD ids: CVE-2024-49909, CVE-2024-47704, CVE-2024-49915, CVE-2024-49918, CVE-2024-49904, CVE-2024-49899, CVE-2024-49893, CVE-2024-49967, CVE-2024-49910, CVE-2024-49907, CVE-2024-49911, CVE-2024-49921, CVE-2024-49914, CVE-2024-49917, CVE-2024-49916, CVE-2024-49898, CVE-2024-49897, CVE-2024-49896, CVE-2024-50264, CVE-2024-49923, CVE-2024-49913, CVE-2024-49906, CVE-2024-49912, CVE-2024-49920, CVE-2024-49905, CVE-2024-49919, CVE-2024-49922, CVE-2024-49908, CVE-2024-53057

Trust: 3.75

Fetched: Jan. 14, 2025, 9:58 a.m., Published: Jan. 13, 2025, 8:52 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: iphone
vendor: apple model: macbook
Related entries in the VARIoT vulnerabilities database: VAR-202412-2453

Trust: 3.75

Fetched: Jan. 14, 2025, 9:57 a.m., Published: Dec. 19, 2024, 8:16 a.m.
Vulnerabilities: path traversal, improper validation
Affected productsExternal IDs
db: NVD ids: CVE-2023-34990, CVE-2024-48889

Trust: 4.75

Fetched: Jan. 14, 2025, 9:56 a.m., Published: Feb. 13, 2024, 7 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: four-faith model: four-faith
vendor: four-faith model: four-faith router
db: NVD ids: CVE-2024-12856