VARIoT news about IoT security

Trust: 4.75

Fetched: Oct. 29, 2023, 9:16 a.m., Published: Oct. 29, 2024, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: cisco model: ios xe
vendor: cisco model: wireless lan controller
vendor: cisco model: cisco ios xe
vendor: cisco model: cisco ios
vendor: cisco model: routers
vendor: cisco model: router
db: NVD ids: CVE-2023-20198

Trust: 3.75

Fetched: Oct. 29, 2023, 9:15 a.m., Published: Oct. 24, 2023, 1:44 p.m.
Vulnerabilities: buffer overflow
Affected productsExternal IDs

Trust: 3.0

Fetched: Oct. 29, 2023, 9:14 a.m., Published: Oct. 23, 2023, 7:35 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: ios xe
vendor: cisco model: ios xe software
vendor: cisco model: routers

Trust: 4.75

Fetched: Oct. 29, 2023, 9:13 a.m., Published: Oct. 19, 2023, 9:56 p.m.
Vulnerabilities: session hijacking
Affected productsExternal IDs
vendor: citrix model: netscaler gateway
vendor: citrix model: application delivery controller
vendor: citrix model: netscaler
vendor: citrix model: netscaler adc
vendor: citrix model: netscaler application delivery controller
vendor: citrix model: gateway
db: NVD ids: CVE-2023-4966

Trust: 5.25

Fetched: Oct. 29, 2023, 9:12 a.m., Published: Oct. 3, 2023, 7:39 a.m.
Vulnerabilities: path traversal, control bypass, cross-site scripting...
Affected productsExternal IDs
vendor: mobileiron model: mobileiron sentry
vendor: mobileiron model: sentry
db: NVD ids: CVE-2023-30534, CVE-2023-39364, CVE-2023-39357, CVE-2023-37941, CVE-2023-38203, CVE-2023-39512, CVE-2023-39360, CVE-2023-29455, CVE-2023-39358, CVE-2023-29454, CVE-2023-38205, CVE-2023-39366, CVE-2023-31132, CVE-2023-32672, CVE-2023-36387, CVE-2023-35078, CVE-2023-39143, CVE-2023-39265, CVE-2023-29457, CVE-2023-39510, CVE-2023-39514, CVE-2023-293000, CVE-2023-39359, CVE-2023-36388, CVE-2023-39515, CVE-2023-38204, CVE-2023-39511, CVE-2023-22513, CVE-2023-4945, CVE-2023-39365, CVE-2023-39362, CVE-2023-4013, CVE-2023-35082, CVE-2023-39264, CVE-2023-39516, CVE-2023-38035, CVE-2023-39513, CVE-2023-39361

Trust: 3.0

Fetched: Oct. 29, 2023, 9:10 a.m., Published: Oct. 3, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: ios xe
vendor: cisco model: cisco ios
vendor: cisco model: ios xe software
vendor: cisco model: cisco ios xe

Trust: 4.5

Fetched: Oct. 29, 2023, 9:09 a.m., Published: Oct. 3, 2023, midnight
Vulnerabilities: brute force attack, command execution
Affected productsExternal IDs
vendor: apple model: watch

Trust: 4.0

Fetched: Oct. 29, 2023, 9:04 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: ios xe
vendor: cisco model: cisco ios
vendor: cisco model: cisco ios xe
db: NVD ids: CVE-2023-20198, CVE-2023-20273

Trust: 3.5

Fetched: Oct. 27, 2023, 9:32 a.m., Published: Oct. 5, 2020, 6:12 p.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
vendor: sourcefire model: snort
vendor: snort model: snort
vendor: cisco model: sd-wan
vendor: cisco model: advanced malware protection

Trust: 4.75

Fetched: Oct. 27, 2023, 9:31 a.m., Published: Oct. 19, 2023, 6:29 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: check point model: check point
db: NVD ids: CVE-2023-38831

Trust: 3.75

Fetched: Oct. 27, 2023, 9:30 a.m., Published: Oct. 18, 2023, 6:48 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: synology model: diskstation
vendor: synology model: diskstation manager
db: NVD ids: CVE-2023-2729

Trust: 4.5

Fetched: Oct. 27, 2023, 9:28 a.m., Published: Aug. 20, 2020, 10:14 a.m.
Vulnerabilities: cross-site scripting, injection attack, sql injection
Affected productsExternal IDs
vendor: essential model: phone

Trust: 4.25

Fetched: Oct. 27, 2023, 9:23 a.m., Published: Oct. 18, 2023, 4:16 p.m.
Vulnerabilities: command execution, code execution
Affected productsExternal IDs
vendor: trend model: antivirus
vendor: trend model: security
vendor: trend micro model: antivirus
vendor: trend micro model: security
db: NVD ids: CVE-2023-42793
Related entries in the VARIoT vulnerabilities database: VAR-202103-0773

Trust: 5.5

Fetched: Oct. 27, 2023, 9:23 a.m., Published: Oct. 23, 2023, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: cisco model: routers
vendor: cisco model: ios xe
db: NVD ids: CVE-2023-20198, CVE-2021-1435, CVE-2023-20273

Trust: 3.25

Fetched: Oct. 27, 2023, 9:21 a.m., Published: Oct. 2, 2023, 11:47 a.m.
Vulnerabilities: default credentials, denial of service
Affected productsExternal IDs
vendor: google model: home
vendor: google model: android
vendor: google model: wifi
vendor: google model: wi-fi router
vendor: apple model: iphone
Related entries in the VARIoT vulnerabilities database: VAR-202310-2564, VAR-202310-0175

Trust: 5.25

Fetched: Oct. 27, 2023, 9:19 a.m., Published: Oct. 16, 2023, 8:38 p.m.
Vulnerabilities: default credentials, privilege escalation, command injection...
Affected productsExternal IDs
vendor: google model: android
vendor: google model: wifi
vendor: tp-link model: gateway
vendor: tp-link model: routers
vendor: citrix model: netscaler adc
vendor: citrix model: netscaler
vendor: citrix model: gateway
vendor: citrix model: netscaler gateway
vendor: d-link model: router
vendor: cisco model: router
vendor: cisco model: netscaler gateway
vendor: cisco model: routers
db: NVD ids: CVE-2023-4966, CVE-2023-43641, CVE-2023-45208, CVE-2023-4967, CVE-2023-42824, CVE-2023-44487, CVE-2023-5217, CVE-2023-38545

Trust: 4.25

Fetched: Oct. 27, 2023, 9:17 a.m., Published: Oct. 17, 2023, 4:16 p.m.
Vulnerabilities: default credentials, privilege escalation
Affected productsExternal IDs
vendor: cisco model: ios xe software
vendor: cisco model: cisco ios
vendor: cisco model: ios xe
vendor: cisco model: cisco ios xe
vendor: cisco model: access points
vendor: cisco model: routers
db: NVD ids: CVE-2023-20198
Related entries in the VARIoT vulnerabilities database: VAR-202103-0773

Trust: 5.5

Fetched: Oct. 27, 2023, 9:16 a.m., Published: Oct. 3, 2023, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: cisco model: guard
vendor: cisco model: routers
vendor: cisco model: ios xe
db: NVD ids: CVE-2023-20198, CVE-2021-1435, CVE-2023-20273

Trust: 3.5

Fetched: Oct. 27, 2023, 9:15 a.m., Published: Oct. 17, 2023, 12:01 a.m.
Vulnerabilities: default credentials, denial of service, service disruption
Affected productsExternal IDs

Trust: 4.75

Fetched: Oct. 27, 2023, 9:13 a.m., Published: Oct. 3, 2023, midnight
Vulnerabilities: privilege escalation, authentication bypass
Affected productsExternal IDs
vendor: cisco model: ios xe software
vendor: cisco model: cisco ios
vendor: cisco model: ios xe
vendor: cisco model: cisco ios xe
vendor: cisco model: routers
db: NVD ids: CVE-2023-20198