VARIoT news about IoT security

Trust: 5.0

Fetched: May 3, 2024, 10:32 a.m., Published: April 19, 2024, 6:06 p.m.
Vulnerabilities: cross-site scripting, denial of service
Affected productsExternal IDs
vendor: zoom model: client
db: NVD ids: CVE-2024-27242, CVE-2024-24694, CVE-2024-27247

Trust: 5.75

Fetched: May 3, 2024, 10:29 a.m., Published: April 3, 2024, midnight
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
vendor: d-link model: dap-2690_firmware
vendor: d-link model: dap-2660_firmware
vendor: d-link model: dap-2690
vendor: d-link model: d-link dap-2330
vendor: d-link model: dap-3662
vendor: d-link model: dap-2330
vendor: d-link model: dap-2553
vendor: d-link model: dap-2695
vendor: d-link model: dap-2695_firmware
vendor: d-link model: dap-2660
vendor: d-link model: dap-2330_firmware
vendor: d-link model: dap-3662_firmware
vendor: d-link model: dap-2553_firmware
vendor: dlink model: dap-2690_firmware
vendor: dlink model: dap-2660_firmware
vendor: dlink model: dap-2690
vendor: dlink model: d-link dap-2330
vendor: dlink model: dap-3662
vendor: dlink model: dap-2330
vendor: dlink model: dap-2553
vendor: dlink model: dap-2695
vendor: dlink model: dap-2695_firmware
vendor: dlink model: dap-2660
vendor: dlink model: dap-2330_firmware
vendor: dlink model: dap-3662_firmware
vendor: dlink model: dap-2553_firmware
db: NVD ids: CVE-2024-28436

Trust: 3.0

Fetched: May 3, 2024, 10:28 a.m., Published: April 17, 2024, 3 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-31497

Trust: 4.5

Fetched: May 3, 2024, 10:25 a.m., Published: April 24, 2024, 10:55 p.m.
Vulnerabilities: code execution, denial of service
Affected productsExternal IDs
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: firepower
vendor: cisco model: firepower threat defense
vendor: cisco model: firepower threat defense software
vendor: cisco model: adaptive security appliance
db: NVD ids: CVE-2024-20353317451, CVE-2024-20359, CVE-2024-20353

Trust: 3.25

Fetched: May 3, 2024, 10:24 a.m., Published: May 3, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android

Trust: 4.75

Fetched: May 3, 2024, 10:24 a.m., Published: -
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: mikrotik model: router
vendor: mikrotik model: routeros
vendor: mikrotik model: mikrotik router
vendor: mikrotik model: winbox
vendor: snort model: snort
db: NVD ids: CVE-2023-30799

Trust: 3.0

Fetched: May 3, 2024, 10:24 a.m., Published: April 9, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: squid model: squid
Related entries in the VARIoT vulnerabilities database: VAR-202404-0070, VAR-202404-0069

Trust: 4.5

Fetched: May 3, 2024, 10:22 a.m., Published: April 15, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: series
vendor: google model: android
vendor: google model: home
vendor: d-link model: dns-325
vendor: d-link model: dns-320l
vendor: d-link model: dns-340l
vendor: d-link model: dns-327l
db: NVD ids: CVE-2023-6320, CVE-2024-3273, CVE-2023-6318, CVE-2023-6317, CVE-2024-3272, CVE-2023-6319
Related entries in the VARIoT vulnerabilities database: VAR-202404-0069, VAR-202404-0070

Trust: 4.75

Fetched: May 3, 2024, 10:21 a.m., Published: April 8, 2024, 6:56 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: d-link model: dns-325
vendor: d-link model: dns-320l
vendor: d-link model: dns-340l
vendor: d-link model: dns-327l
db: NVD ids: CVE-2024-3272, CVE-2024-3273

Trust: 5.5

Fetched: May 3, 2024, 10:14 a.m., Published: April 24, 2024, 10:57 a.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo model: networks
vendor: siemens model: ruggedcom
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
db: NVD ids: CVE-2024-3400
Related entries in the VARIoT vulnerabilities database: VAR-202404-0069, VAR-202404-0070

Trust: 3.75

Fetched: May 3, 2024, 10:13 a.m., Published: April 12, 2024, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-3272, CVE-2024-3273

Trust: 4.25

Fetched: May 3, 2024, 10:11 a.m., Published: April 22, 2024, 11:16 a.m.
Vulnerabilities: cross-site scripting, sql injection
Affected productsExternal IDs
vendor: trend model: security

Trust: 3.75

Fetched: May 3, 2024, 10:11 a.m., Published: May 3, 2401, midnight
Vulnerabilities: replay attack
Affected productsExternal IDs
vendor: sonos model: sonos

Trust: 3.5

Fetched: May 3, 2024, 10:09 a.m., Published: April 10, 2024, 2:24 p.m.
Vulnerabilities: command injection, code execution, denial of service
Affected productsExternal IDs
vendor: d-link model: dns-325
vendor: d-link model: dns-340l
vendor: d-link model: dns-320l
vendor: d-link model: dns-327l

Trust: 3.75

Fetched: May 3, 2024, 10:06 a.m., Published: -
Vulnerabilities: sql injection
Affected productsExternal IDs
vendor: apple model: mac os

Trust: 3.5

Fetched: May 3, 2024, 10:03 a.m., Published: May 3, 2024, midnight
Vulnerabilities: input validation vulnerability, denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2019-1010083, CVE-2018-1000656

Trust: 3.25

Fetched: May 3, 2024, 9:58 a.m., Published: April 26, 2024, 9:56 a.m.
Vulnerabilities: use after free, sql injection
Affected productsExternal IDs
vendor: cisco model: cisco ios
vendor: cisco model: routers
vendor: cisco model: router
vendor: cisco model: 4351
vendor: cisco model: vedge
vendor: cisco model: advanced malware protection
vendor: cisco model: wan manager
vendor: cisco model: 4321
vendor: cisco model: intrusion prevention system
vendor: cisco model: series
vendor: cisco model: isr4331
vendor: cisco model: umbrella
vendor: cisco model: sd-wan
vendor: cisco model: ios xe
vendor: cisco model: threat response
vendor: cisco model: sd-wan solution
vendor: cisco model: cisco sd-wan
vendor: cisco model: catalyst
vendor: snort model: snort
vendor: snort.org model: snort

Trust: 3.25

Fetched: May 3, 2024, 9:58 a.m., Published: April 12, 2024, midnight
Vulnerabilities: command injection
Affected productsExternal IDs

Trust: 4.5

Fetched: May 3, 2024, 9:57 a.m., Published: April 11, 2024, 5:58 p.m.
Vulnerabilities: information disclosure
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
db: NVD ids: CVE-2024-29748, CVE-2024-29745

Trust: 5.5

Fetched: May 3, 2024, 9:54 a.m., Published: May 3, 2024, midnight
Vulnerabilities: buffer overflow, code execution
Affected productsExternal IDs
vendor: aruba networks model: arubaos
vendor: aruba model: arubaos
db: NVD ids: CVE-2024-26305, CVE-2024-26304, CVE-2024-33511, CVE-2024-33512