VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202108-2051, VAR-202212-1751

Trust: 5.25

Fetched: April 28, 2023, 9:20 a.m., Published: March 31, 2023, midnight
Vulnerabilities: information leak, code execution, privilege escalation
Affected productsExternal IDs
vendor: apple model: webkit
vendor: apple model: safari
vendor: google model: android
vendor: google model: chrome
vendor: samsung model: mobile
vendor: avast model: antivirus
db: NVD ids: CVE-2022-3038, CVE-2021-30900, CVE-2022-38181, CVE-2022-3723, CVE-2022-4262, CVE-2023-0266, CVE-2022-22706, CVE-2022-4135, CVE-2022-42856

Trust: 3.75

Fetched: April 28, 2023, 9:20 a.m., Published: April 21, 2023, 3:16 p.m.
Vulnerabilities: command injection, os command injection, code execution
Affected productsExternal IDs

Trust: 4.25

Fetched: April 28, 2023, 9:19 a.m., Published: -
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2022-41974, CVE-2022-41973

Trust: 4.25

Fetched: April 28, 2023, 9:18 a.m., Published: April 14, 2023, 1:29 p.m.
Vulnerabilities: data injection, path traversal, entity injection...
Affected productsExternal IDs
vendor: hitachi model: web server
vendor: opc foundation model: local discovery server
vendor: siemens model: simatic wincc runtime professional
vendor: siemens model: tia portal
vendor: siemens model: telecontrol server basic
vendor: siemens model: modbus tcp
vendor: siemens model: simatic process historian opc ua server
vendor: siemens model: simatic wincc
vendor: siemens model: openpcs
vendor: siemens model: openpcs 7
vendor: siemens model: jt2go
vendor: siemens model: wincc
vendor: siemens model: scalance
vendor: siemens model: simatic wincc runtime
vendor: siemens model: process historian
vendor: siemens model: sicam
vendor: siemens model: siprotec
vendor: siemens model: teamcenter visualization
vendor: siemens model: simatic net
vendor: siemens model: teamcenter
vendor: siemens model: simatic
vendor: siemens model: scalance x-200irt
vendor: siemens model: siprotec 5
vendor: siemens model: simatic net pc
vendor: siemens model: scalance x-200
vendor: siemens model: simatic net pc software
vendor: siemens model: sicam a8000

Trust: 4.0

Fetched: April 28, 2023, 9:18 a.m., Published: April 6, 2023, 5:40 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: adaptive security appliance software
vendor: cisco model: firepower
vendor: cisco model: ios xe
vendor: cisco model: cisco ios
vendor: cisco model: firepower threat defense
vendor: cisco model: asa software
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: ios xe software
vendor: cisco model: adaptive security appliance
vendor: cisco model: cisco adaptive security appliance software
vendor: cisco model: ios software
vendor: cisco model: firepower threat defense software

Trust: 4.75

Fetched: April 28, 2023, 9:17 a.m., Published: March 31, 2023, 10:30 a.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2023-22809

Trust: 3.0

Fetched: April 28, 2023, 9:16 a.m., Published: April 28, 4949, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: axis model: gear

Trust: 3.25

Fetched: April 28, 2023, 9:16 a.m., Published: Feb. 18, 2019, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2019-8372

Trust: 5.75

Fetched: April 28, 2023, 9:15 a.m., Published: March 23, 2023, 6:18 p.m.
Vulnerabilities: command injection, privilege escalation, denial of service
Affected productsExternal IDs
vendor: cisco model: ios xe
vendor: cisco model: cisco ios
vendor: cisco model: iox application
vendor: cisco model: ios xe software
vendor: cisco model: ios xe sd-wan software
vendor: cisco model: cisco ios xe
vendor: cisco model: sd-wan
db: NVD ids: CVE-2023-20035, CVE-2023-20065, CVE-2023-20072, CVE-2023-20080, CVE-2023-20027

Trust: 4.0

Fetched: April 28, 2023, 9:15 a.m., Published: Feb. 22, 2023, 3:50 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: cisco model: cisco nx-os
vendor: cisco model: series switches
vendor: cisco model: nexus
vendor: cisco model: nx-os
vendor: cisco model: cisco nexus 9000 series
vendor: cisco model: nexus 3000
vendor: cisco model: nx-os software
vendor: cisco model: nexus 9000
vendor: cisco model: nexus 1000v
vendor: cisco model: series
vendor: cisco model: 1000v
vendor: cisco model: nexus 7000
vendor: cisco model: nexus 9000 series

Trust: 3.75

Fetched: April 28, 2023, 9:15 a.m., Published: April 19, 2023, 3:47 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: cisco model: staros
vendor: cisco model: cisco staros
Related entries in the VARIoT vulnerabilities database: VAR-202304-0672

Trust: 4.75

Fetched: April 28, 2023, 9:15 a.m., Published: April 1, 2023, midnight
Vulnerabilities: command injection, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2023-28489
Related entries in the VARIoT vulnerabilities database: VAR-201707-0964

Trust: 3.5

Fetched: April 28, 2023, 9:14 a.m., Published: April 28, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: cisco ios
vendor: cisco model: cisco routers
vendor: cisco model: router
vendor: cisco model: routers
db: NVD ids: CVE-2017-6742

Trust: 3.75

Fetched: April 28, 2023, 9:14 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2023-1752, CVE-2023-1749, CVE-2023-1750, CVE-2023-1748, CVE-2023-1751

Trust: 4.25

Fetched: April 28, 2023, 9:13 a.m., Published: April 4, 2023, 4:35 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2022-27597, CVE-2022-27598
Related entries in the VARIoT vulnerabilities database: VAR-202303-2580

Trust: 3.5

Fetched: April 26, 2023, 9:14 a.m., Published: March 30, 2023, 1:39 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android
vendor: sophos model: firewall
db: NVD ids: CVE-2023-29059

Trust: 3.0

Fetched: April 26, 2023, 9:12 a.m., Published: Dec. 20, 2019, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2018-3646, CVE-2018-12127, CVE-2022-21123, CVE-2022-21125, CVE-2022-21127, CVE-2018-3639, CVE-2017-5753, CVE-2018-3615, CVE-2018-11091, CVE-2019-11135, CVE-2022-21166, CVE-2018-3620, CVE-2017-5754, CVE-2018-12126, CVE-2017-5715, CVE-2018-12130
Related entries in the VARIoT vulnerabilities database: VAR-202304-0672

Trust: 5.25

Fetched: April 26, 2023, 9:10 a.m., Published: -
Vulnerabilities: data injection, integer overflow, memory corruption...
Affected productsExternal IDs
vendor: google model: chrome
vendor: siemens model: scalance
vendor: siemens model: sicam a8000
vendor: siemens model: sicam
vendor: siemens model: scalance x-200
db: NVD ids: CVE-2020-14521, CVE-2023-28489, CVE-2023-2033
Related entries in the VARIoT vulnerabilities database: VAR-202303-1268

Trust: 4.75

Fetched: April 26, 2023, 9:10 a.m., Published: April 24, 2023, 3:03 p.m.
Vulnerabilities: code execution, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2023-1389

Trust: 6.5

Fetched: April 26, 2023, 9:10 a.m., Published: April 24, 2023, 5:46 p.m.
Vulnerabilities: case sensitivity vulnerability, code execution, authentication bypass
Affected productsExternal IDs
vendor: schneider electric model: monitor
vendor: schneider model: monitor
db: NVD ids: CVE-2023-29411, CVE-2023-29413, CVE-2023-29412