VARIoT news about IoT security

Trust: 5.25

Fetched: June 10, 2025, 9:21 a.m., Published: June 6, 2025, 9:41 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2025-0324

Trust: 6.0

Fetched: June 10, 2025, 9:20 a.m., Published: June 6, 2025, 10:42 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: axis model: axis
db: NVD ids: CVE-2025-0358

Trust: 5.0

Fetched: June 10, 2025, 9:19 a.m., Published: June 4, 2025, 3:54 p.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
vendor: cisco model: intelligent contact management
vendor: cisco model: unified intelligent contact management
vendor: cisco model: unified intelligent contact management enterprise

Trust: 3.5

Fetched: June 10, 2025, 9:18 a.m., Published: June 3, 2025, 1 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: huawei model: huawei
vendor: solar model: sunny webbox
vendor: solar model: webbox
db: NVD ids: CVE-2023-23333, CVE-2023-29919, CVE-2022-29303, CVE-2022-40881

Trust: 4.75

Fetched: June 10, 2025, 9:17 a.m., Published: June 9, 2025, 4:27 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: google chrome
vendor: google model: chrome
vendor: google model: android
vendor: apple model: macos
vendor: apple model: iphone
db: NVD ids: CVE-2025-5419

Trust: 3.75

Fetched: June 10, 2025, 9:04 a.m., Published: June 8, 2025, 6:04 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: home
vendor: google model: android
vendor: google model: pixel
vendor: oneplus model: oneplus
vendor: samsung model: samsung
vendor: samsung model: android phone
db: NVD ids: CVE-2025-26441, CVE-2025-26453, CVE-2025-26445, CVE-2025-26443
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132

Trust: 3.75

Fetched: June 8, 2025, 10 a.m., Published: June 6, 2025, 3:10 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2022-42475, CVE-2024-21762, CVE-2023-27997, CVE-2024-55591

Trust: 3.0

Fetched: June 8, 2025, 10 a.m., Published: June 5, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android

Trust: 3.75

Fetched: June 8, 2025, 10 a.m., Published: May 22, 2025, 4:04 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: hitachi model: jp1/it desktop management
vendor: hitachi model: device manager
db: NVD ids: CVE-2025-27523

Trust: 5.25

Fetched: June 8, 2025, 9:46 a.m., Published: June 1, 2025, midnight
Vulnerabilities: memory corruption, code execution, object injection
Affected productsExternal IDs
vendor: google model: home
vendor: google model: android
vendor: google model: chrome
vendor: google model: nexus
vendor: cisco model: series
vendor: cisco model: nexus
vendor: cisco model: identity services engine
db: NVD ids: CVE-2025-20286, CVE-2020-35198, CVE-2025-20261, CVE-2020-28895, CVE-2025-20163, CVE-2025-49113

Trust: 3.75

Fetched: June 8, 2025, 9:46 a.m., Published: May 14, 2025, 8:15 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: note
vendor: samsung model: samsung galaxy
vendor: samsung model: samsung
vendor: samsung model: galaxy
db: NVD ids: CVE-2024-58101

Trust: 3.25

Fetched: June 8, 2025, 9:39 a.m., Published: June 8, 2025, 5:49 a.m.
Vulnerabilities: privilege escalation, default credentials
Affected productsExternal IDs
vendor: snort model: snort
vendor: zabbix model: zabbix
vendor: node.js model: node.js

Trust: 4.5

Fetched: June 8, 2025, 9:37 a.m., Published: June 4, 2025, 2:08 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: android
vendor: trend model: security
db: NVD ids: CVE-2025-21480, CVE-2025-21479, CVE-2025-27038

Trust: 4.25

Fetched: June 8, 2025, 9:37 a.m., Published: May 21, 2025, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: lexmark model: lexmark

Trust: 3.5

Fetched: June 8, 2025, 9:35 a.m., Published: June 8, 2025, midnight
Vulnerabilities: use after free, privilege escalation, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2024-30105, CVE-2024-38095, CVE-2024-38081, CVE-2024-43485, CVE-2024-20672, CVE-2024-0056, CVE-2024-43483, CVE-2024-35264

Trust: 5.25

Fetched: June 8, 2025, 9:34 a.m., Published: June 15, 2025, midnight
Vulnerabilities: input validation issue, integer overflow, code execution...
Affected productsExternal IDs
vendor: apple model: icloud
vendor: apple model: safari
vendor: apple model: macos
vendor: google model: chrome
vendor: google model: google chrome
vendor: trend model: security
vendor: trend micro model: security
db: NVD ids: CVE-2025-24222, CVE-2025-26466, CVE-2025-31219, CVE-2025-24142, CVE-2025-26465, CVE-2025-31258, CVE-2025-31223, CVE-2025-31215, CVE-2025-31221, CVE-2025-31213, CVE-2025-31239, CVE-2025-24223, CVE-2025-31209, CVE-2025-31204, CVE-2025-31246, CVE-2025-31245, CVE-2025-31251, CVE-2025-31208, CVE-2025-31257, CVE-2025-31234, CVE-2025-31205, CVE-2025-31233, CVE-2025-31237, CVE-2025-31250, CVE-2025-31249, CVE-2025-31238, CVE-2025-31256, CVE-2025-31212, CVE-2024-8176, CVE-2025-24274, CVE-2025-31218, CVE-2025-31232, CVE-2025-31222, CVE-2025-24213, CVE-2025-31242, CVE-2025-31220, CVE-2025-31260, CVE-2025-31240, CVE-2025-31259, CVE-2025-31244, CVE-2025-31224, CVE-2025-31236, CVE-2025-31247, CVE-2025-31241, CVE-2025-31217, CVE-2025-30440, CVE-2025-31235, CVE-2025-30443, CVE-2025-31226, CVE-2025-31206

Trust: 5.5

Fetched: June 8, 2025, 9:31 a.m., Published: June 4, 2025, 3:54 p.m.
Vulnerabilities: path traversal, code execution
Affected productsExternal IDs
vendor: cisco model: unified ccx
vendor: cisco model: cisco unified contact center express
vendor: cisco model: unified contact center express
db: NVD ids: CVE-2025-20276, CVE-2025-20279, CVE-2025-20277

Trust: 3.25

Fetched: June 8, 2025, 9:30 a.m., Published: June 1, 2025, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: wifi
vendor: google model: home
vendor: samsung smartthings model: samsung
vendor: trend model: security
vendor: samsung model: samsung

Trust: 3.0

Fetched: June 8, 2025, 9:23 a.m., Published: June 4, 2025, noon
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: nexus

Trust: 3.5

Fetched: June 8, 2025, 9:21 a.m., Published: June 2, 2025, 4:26 p.m.
Vulnerabilities: traffic interception, cross-site scripting, privilege escalation...
Affected productsExternal IDs