VARIoT news about IoT security

Trust: 3.25

Fetched: March 13, 2024, 9:52 a.m., Published: Oct. 8, 2023, 6:06 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: ecobee model: ecobee smart thermostat
vendor: ecobee model: smart thermostat
vendor: chamberlain model: myq garage
vendor: ring model: video doorbells
vendor: nest model: learning thermostat

Trust: 3.0

Fetched: March 13, 2024, 9:50 a.m., Published: Sept. 14, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: symantec model: endpoint protection
vendor: symantec model: symantec endpoint protection

Trust: 4.5

Fetched: March 13, 2024, 9:50 a.m., Published: Feb. 14, 2024, 6:24 a.m.
Vulnerabilities: security feature bypass, code injection, feature bypass...
Affected productsExternal IDs
db: NVD ids: CVE-2024-21412, CVE-2024-21351

Trust: 3.0

Fetched: March 13, 2024, 9:47 a.m., Published: Feb. 28, 2024, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs

Trust: 3.25

Fetched: March 13, 2024, 9:46 a.m., Published: March 13, 2024, 5:21 a.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-24785

Trust: 4.25

Fetched: March 13, 2024, 9:46 a.m., Published: March 11, 2024, 2:30 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: qnap model: qnap qts
db: NVD ids: CVE-2024-21899, CVE-2024-21901, CVE-2024-21900
Related entries in the VARIoT vulnerabilities database: VAR-201905-0112

Trust: 3.0

Fetched: March 13, 2024, 9:45 a.m., Published: March 1, 2024, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2019-6572
Related entries in the VARIoT vulnerabilities database: VAR-202002-0214

Trust: 4.0

Fetched: March 13, 2024, 9:44 a.m., Published: March 13, 2024, midnight
Vulnerabilities: -

Trust: 4.0

Fetched: March 13, 2024, 9:43 a.m., Published: March 12, 2024, 4:11 p.m.
Vulnerabilities: use after free
Affected productsExternal IDs
db: NVD ids: CVE-2023-52491

Trust: 3.25

Fetched: March 13, 2024, 9:43 a.m., Published: March 6, 2024, 4 p.m.
Vulnerabilities: path traversal
Affected productsExternal IDs

Trust: 3.0

Fetched: March 13, 2024, 9:42 a.m., Published: March 13, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2024-21887, CVE-2024-21893, CVE-2023-46805

Trust: 4.0

Fetched: March 13, 2024, 9:41 a.m., Published: March 6, 2024, 5:15 p.m.
Vulnerabilities: code injection, uncontrolled search path
Affected productsExternal IDs

Trust: 4.75

Fetched: March 13, 2024, 9:40 a.m., Published: March 12, 2024, 4:31 p.m.
Vulnerabilities: path traversal, buffer overflow
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2023-27997, CVE-2022-41328, CVE-2024-21762

Trust: 5.25

Fetched: March 13, 2024, 9:40 a.m., Published: -
Vulnerabilities: authentication bypass, information exposure
Affected productsExternal IDs
vendor: google model: android
vendor: google model: home
db: NVD ids: CVE-2023-45866

Trust: 4.25

Fetched: March 13, 2024, 9:39 a.m., Published: Jan. 11, 2017, midnight
Vulnerabilities: default password
Affected productsExternal IDs
vendor: delegate model: delegate

Trust: 3.5

Fetched: March 13, 2024, 9:33 a.m., Published: Dec. 13, 2022, 4:14 p.m.
Vulnerabilities: file inclusion, default credentials, remote file inclusion
Affected productsExternal IDs
vendor: google model: wifi

Trust: 5.25

Fetched: March 13, 2024, 9:32 a.m., Published: Feb. 11, 2024, midnight
Vulnerabilities: request forgery, condition checking attack, code execution...
Affected productsExternal IDs
vendor: huawei model: huawei
vendor: trend model: antivirus
vendor: trend model: security
vendor: tesla model: model
vendor: filezilla model: server
vendor: palo model: firewall
vendor: palo model: ssl vpn
vendor: palo model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: ssl vpn
vendor: palo alto networks model: networks
vendor: fortigate model: fortios
vendor: zyxel model: vpn1000
vendor: zyxel model: vpn50
vendor: zyxel model: vpn100
vendor: zyxel model: vpn300
db: NVD ids: CVE-2024-21893, CVE-2024-21762

Trust: 4.25

Fetched: March 13, 2024, 9:30 a.m., Published: Dec. 14, 2023, midnight
Vulnerabilities: session hijacking, buffer overflow
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo model: networks
vendor: citrix model: gateway
vendor: citrix model: netscaler adc
vendor: citrix model: netscaler
vendor: citrix model: netscaler gateway
vendor: citrix model: netscaler application delivery controller
vendor: citrix model: application delivery controller
db: NVD ids: CVE-2023-4966, CVE-2023-4967
Related entries in the VARIoT vulnerabilities database: VAR-202310-0175

Trust: 5.0

Fetched: March 13, 2024, 9:30 a.m., Published: Feb. 8, 2024, 11:11 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2024-23113, CVE-2023-47537, CVE-2023-44487, CVE-2024-21762

Trust: 3.0

Fetched: March 13, 2024, 9:24 a.m., Published: Feb. 9, 2024, 6:13 p.m.
Vulnerabilities: entity injection
Affected productsExternal IDs
db: NVD ids: CVE-2024-22024