VARIoT news about IoT security

Trust: 4.75

Fetched: Dec. 3, 2023, 9:28 a.m., Published: Nov. 27, 2023, 11:54 a.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
vendor: codesys model: codesys
vendor: codesys model: web server
vendor: codesys model: control

Trust: 5.5

Fetched: Dec. 3, 2023, 9:26 a.m., Published: Dec. 1, 2023, midnight
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: delta electronics model: electronics dopsoft
vendor: delta electronics model: dopsoft
vendor: trend model: security
vendor: trend micro model: security
vendor: delta model: electronics dopsoft
vendor: delta model: dopsoft
db: NVD ids: CVE-2023-5944

Trust: 3.25

Fetched: Dec. 3, 2023, 9:22 a.m., Published: Sept. 11, 2023, midnight
Vulnerabilities: command execution, buffer overflow, privilege escalation...
Affected productsExternal IDs

Trust: 4.25

Fetched: Dec. 3, 2023, 9:20 a.m., Published: Nov. 29, 2023, midnight
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: lenovo model: system
vendor: lenovo model: bios
db: NVD ids: CVE-2022-21894, CVE-2023-24932

Trust: 3.5

Fetched: Dec. 3, 2023, 9:16 a.m., Published: June 4, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: google chrome
vendor: google model: chrome
db: NVD ids: CVE-2020-15992, CVE-2020-16011, CVE-2020-26971

Trust: 3.0

Fetched: Dec. 3, 2023, 9:15 a.m., Published: Nov. 20, 2017, 5:21 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2017-5711, CVE-2017-5708, CVE-2017-5709, CVE-2017-5705, CVE-2017-5707, CVE-2017-5712, CVE-2017-5710, CVE-2017-5706

Trust: 4.75

Fetched: Dec. 3, 2023, 9:07 a.m., Published: Dec. 7, 2023, midnight
Vulnerabilities: authentication bypass, authentication vulnerability, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2023-4474, CVE-2023-35138, CVE-2023-35137, CVE-2023-4473, CVE-2023-37928, CVE-2023-37927

Trust: 4.75

Fetched: Dec. 3, 2023, 9:07 a.m., Published: Dec. 1, 2023, 12:38 a.m.
Vulnerabilities: integer overflow
Affected productsExternal IDs
vendor: google model: chrome
vendor: apple model: safari
vendor: apple model: macos
vendor: apple model: webkit
db: NVD ids: CVE-2023-6345, CVE-2023-42917, CVE-2023-42916

Trust: 3.5

Fetched: Dec. 1, 2023, 9:06 a.m., Published: Nov. 28, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: blackberry model: smartphone
vendor: blackberry model: curve
vendor: blackberry model: blackberry

Trust: 3.75

Fetched: Dec. 1, 2023, 9:05 a.m., Published: Nov. 29, 2023, 2:42 p.m.
Vulnerabilities: device impersonation
Affected productsExternal IDs

Trust: 5.75

Fetched: Dec. 1, 2023, 9:05 a.m., Published: Dec. 1, 2023, 6:22 a.m.
Vulnerabilities: authentication bypass, command injection
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2023-37927, CVE-2023-4473, CVE-2023-35138, CVE-2023-37928, CVE-2023-4474, CVE-2023-35137

Trust: 4.75

Fetched: Dec. 1, 2023, 9:04 a.m., Published: -
Vulnerabilities: device impersonation
Affected productsExternal IDs
vendor: lenovo model: system
vendor: lenovo model: thinkpad
db: NVD ids: CVE-2023-24023
Related entries in the VARIoT vulnerabilities database: VAR-201808-0370, VAR-201703-1246, VAR-201802-0484, VAR-202108-1299, VAR-202008-0248

Trust: 4.5

Fetched: Dec. 1, 2023, 9:03 a.m., Published: Dec. 1, 2023, midnight
Vulnerabilities: cross-site scripting, sql injection
Affected productsExternal IDs
vendor: trend model: security
db: NVD ids: CVE-2018-14781, CVE-2017-7269, CVE-2017-12725, CVE-2019-3463, CVE-2021-33882, CVE-2020-1472

Trust: 5.25

Fetched: Dec. 1, 2023, 9:01 a.m., Published: Nov. 30, 2023, midnight
Vulnerabilities: authentication bypass, code execution, command injection
Affected productsExternal IDs
vendor: zyxel model: nas 326
vendor: zyxel model: nas 326 firmware
vendor: zyxel model: nas540
vendor: zyxel model: nas542
vendor: zyxel model: nas326
db: NVD ids: CVE-2023-27992, CVE-2023-4473

Trust: 4.5

Fetched: Nov. 29, 2023, 9:16 a.m., Published: Nov. 7, 2023, midnight
Vulnerabilities: buffer overflow, privilege management vulnerability, cross-site scripting...
Affected productsExternal IDs
db: NVD ids: CVE-2023-5960, CVE-2023-35139, CVE-2023-4398, CVE-2023-35136, CVE-2023-37926, CVE-2023-5797, CVE-2023-37925, CVE-2023-5650, CVE-2023-4397

Trust: 3.25

Fetched: Nov. 29, 2023, 9:15 a.m., Published: Nov. 10, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: dell model: bios

Trust: 3.25

Fetched: Nov. 29, 2023, 9:15 a.m., Published: Nov. 10, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: dell model: bios

Trust: 4.75

Fetched: Nov. 29, 2023, 9:13 a.m., Published: Nov. 1, 2023, midnight
Vulnerabilities: path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2023-5885

Trust: 3.0

Fetched: Nov. 29, 2023, 9:12 a.m., Published: Nov. 22, 2023, 2:01 p.m.
Vulnerabilities: default credentials
Affected productsExternal IDs

Trust: 5.25

Fetched: Nov. 29, 2023, 9:09 a.m., Published: Nov. 1, 2023, midnight
Vulnerabilities: path traversal, code execution
Affected productsExternal IDs
vendor: trend model: security
vendor: trend micro model: security
db: NVD ids: CVE-2023-47279, CVE-2023-47207, CVE-2023-39226, CVE-2023-46690