VARIoT news about IoT security

Trust: 4.75

Fetched: Feb. 8, 2023, 9:18 a.m., Published: Nov. 23, 2022, 12:32 p.m.
Vulnerabilities: code execution, information disclosure
Affected productsExternal IDs
vendor: realtek model: realtek sdk
db: NVD ids: CVE-2021-33558, CVE-2017-9833

Trust: 3.25

Fetched: Feb. 8, 2023, 9:17 a.m., Published: May 6, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2022-27596

Trust: 3.0

Fetched: Feb. 8, 2023, 9:16 a.m., Published: Feb. 3, 2023, midnight
Vulnerabilities: code execution, authentication bypass, privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2023-20854

Trust: 5.5

Fetched: Feb. 8, 2023, 9:16 a.m., Published: -
Vulnerabilities: request forgery, improper access control, cross-site scripting...
Affected productsExternal IDs
vendor: cisco model: routers
vendor: cisco model: cisco asyncos
vendor: cisco model: cisco expressway
vendor: cisco model: data center network manager
vendor: cisco model: cisco prime infrastructure
vendor: cisco model: identity services engine
vendor: cisco model: unified communications manager session management edition
vendor: cisco model: iox application
vendor: cisco model: rv042
vendor: cisco model: expressway
vendor: cisco model: unified communications manager
vendor: cisco model: cisco prime data center network manager
vendor: cisco model: cisco identity services engine
vendor: cisco model: prime infrastructure
vendor: cisco model: unified communications
vendor: cisco model: ip phone 7800
vendor: cisco model: rv016
vendor: cisco model: industrial network director
vendor: cisco model: cisco iox application
vendor: cisco model: cisco telepresence video communication server
vendor: cisco model: asyncos
vendor: cisco model: expressway series
vendor: cisco model: prime data center network manager
vendor: cisco model: cisco email security appliance
vendor: cisco model: cisco telepresence
vendor: cisco model: telepresence
vendor: cisco model: cisco unified communications manager
vendor: cisco model: small business
vendor: cisco model: cisco industrial network director
vendor: cisco model: cisco iox
vendor: cisco model: asyncos software
vendor: cisco model: rv042g
vendor: cisco model: series
vendor: cisco model: ip phone
vendor: cisco model: cisco small business
vendor: cisco model: email security appliance
vendor: cisco model: telepresence video communication server
vendor: cisco model: rv082
db: NVD ids: CVE-2022-20965, CVE-2023-20021, CVE-2015-0666, CVE-2022-20964, CVE-2023-20057, CVE-2023-20076, CVE-2022-20807, CVE-2022-20809, CVE-2023-20018, CVE-2022-20951, CVE-2023-20022, CVE-2022-20967, CVE-2023-20026, CVE-2023-20025, CVE-2023-20038, CVE-2023-20030, CVE-2022-20956, CVE-2022-20822, CVE-2022-20958, CVE-2022-20966, CVE-2023-20040, CVE-2023-20068, CVE-2023-20010, CVE-2023-20023, CVE-2022-20806, CVE-2023-20037
db: CISCO ids: CISCO-SA-20150401-DCNM

Trust: 3.5

Fetched: Feb. 8, 2023, 9:15 a.m., Published: Feb. 1, 2023, midnight
Vulnerabilities: code execution, cross-site scripting, directory traversal...
Affected productsExternal IDs

Trust: 5.5

Fetched: Feb. 8, 2023, 9:15 a.m., Published: Feb. 1, 2023, 8:46 p.m.
Vulnerabilities: code execution, command injection, buffer overflow
Affected productsExternal IDs
vendor: asus model: asus
vendor: asus model: routers
db: NVD ids: CVE-2021-35394
Related entries in the VARIoT vulnerabilities database: VAR-202301-0961, VAR-202301-0962

Trust: 4.75

Fetched: Feb. 8, 2023, 9:14 a.m., Published: Jan. 12, 2023, 1:03 a.m.
Vulnerabilities: improper validation
Affected productsExternal IDs
vendor: cisco model: routers
vendor: cisco model: rv042
vendor: cisco model: rv016
vendor: cisco model: small business
vendor: cisco model: rv042g
vendor: cisco model: cisco small business
vendor: cisco model: rv082
vendor: cisco systems model: routers
vendor: cisco systems model: rv042
vendor: cisco systems model: rv016
vendor: cisco systems model: small business
vendor: cisco systems model: rv042g
vendor: cisco systems model: cisco small business
vendor: cisco systems model: rv082
db: NVD ids: CVE-2023-20026, CVE-2023-20025

Trust: 3.5

Fetched: Feb. 8, 2023, 9:14 a.m., Published: -
Vulnerabilities: code injection, sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2022-27596
Related entries in the VARIoT vulnerabilities database: VAR-202302-0804, VAR-202302-0730, VAR-202302-0689, VAR-202302-0870, VAR-202302-0627

Trust: 4.25

Fetched: Feb. 8, 2023, 9:13 a.m., Published: Feb. 8, 2023, midnight
Vulnerabilities: code execution, information disclosure, denial of service
Affected productsExternal IDs
vendor: google model: android
vendor: google model: pixel
vendor: google model: wifi
vendor: motorola model: android
vendor: motorola model: motorola
vendor: samsung model: mobile
vendor: samsung model: notes
vendor: huawei model: huawei
db: NVD ids: CVE-2023-20932, CVE-2022-20455, CVE-2022-20481, CVE-2023-20946, CVE-2022-33233, CVE-2022-43680, CVE-2023-20943, CVE-2022-33306, CVE-2022-20443, CVE-2022-34145, CVE-2023-20945, CVE-2022-47331, CVE-2022-33277, CVE-2023-20948, CVE-2023-20602, CVE-2023-20933, CVE-2022-33221, CVE-2022-40512, CVE-2022-33280, CVE-2022-47339, CVE-2022-40502, CVE-2023-20934, CVE-2022-33248, CVE-2022-40514, CVE-2022-33243, CVE-2022-20551, CVE-2023-20944, CVE-2023-20940, CVE-2022-34146, CVE-2022-33232, CVE-2022-33271, CVE-2023-20942, CVE-2023-20939

Trust: 4.25

Fetched: Feb. 8, 2023, 9:13 a.m., Published: Feb. 3, 2023, 5:57 p.m.
Vulnerabilities: path traversal
Affected productsExternal IDs

Trust: 5.75

Fetched: Feb. 8, 2023, 9:12 a.m., Published: Jan. 24, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: android
vendor: google model: pixel
db: NVD ids: CVE-2022-38181
Related entries in the VARIoT vulnerabilities database: VAR-202204-2027

Trust: 5.75

Fetched: Feb. 8, 2023, 9:12 a.m., Published: April 28, 2022, midnight
Vulnerabilities: denial of service, privilege escalation
Affected productsExternal IDs
vendor: cisco model: firepower
vendor: cisco model: firepower management center
vendor: cisco model: telepresence
vendor: cisco model: firepower threat defense
vendor: cisco model: expressway
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: adaptive security appliance
db: NVD ids: CVE-2022-20746
Related entries in the VARIoT vulnerabilities database: VAR-202301-0986, VAR-202301-0985

Trust: 4.0

Fetched: Feb. 8, 2023, 9:12 a.m., Published: Jan. 11, 2023, 3:47 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: cisco roomos
vendor: cisco model: cisco telepresence
vendor: cisco model: telepresence
vendor: cisco model: telepresence collaboration endpoint
vendor: cisco model: roomos
db: NVD ids: CVE-2023-20002, CVE-2023-20008

Trust: 4.75

Fetched: Feb. 8, 2023, 9:12 a.m., Published: Jan. 12, 2023, 4:07 p.m.
Vulnerabilities: code execution, denial of service
Affected productsExternal IDs
vendor: cisco model: routers
vendor: cisco model: rv340
vendor: cisco model: rv345
vendor: cisco model: rv340w
vendor: cisco model: rv345p
vendor: cisco model: rv345p dual wan gigabit vpn routers

Trust: 5.75

Fetched: Feb. 8, 2023, 9:11 a.m., Published: Dec. 1, 2022, 9:22 a.m.
Vulnerabilities: code execution, weak password
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2022-45482, CVE-2022-45481, CVE-2022-45477, CVE-2022-45479
Related entries in the VARIoT vulnerabilities database: VAR-202212-1751

Trust: 4.5

Fetched: Feb. 8, 2023, 9:11 a.m., Published: Jan. 22, 2023, 9:12 p.m.
Vulnerabilities: code execution, information disclosure, security bypass
Affected productsExternal IDs
vendor: apple model: safari
vendor: apple model: watchos
vendor: apple model: webkit
vendor: apple model: macos
vendor: apple model: icloud
vendor: apple model: iphone
vendor: apple model: tvos
db: NVD ids: CVE-2022-42856

Trust: 3.5

Fetched: Feb. 8, 2023, 9:10 a.m., Published: Feb. 6, 2023, 9:22 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2022-31699, CVE-2022-31697, CVE-2022-31698, CVE-2021-21974, CVE-2022-31696

Trust: 4.75

Fetched: Feb. 7, 2023, 9:18 a.m., Published: Jan. 31, 2023, 4:39 a.m.
Vulnerabilities: sql injection, code injection, injection attack
Affected productsExternal IDs
db: NVD ids: CVE-2022-27596

Trust: 3.75

Fetched: Feb. 7, 2023, 9:18 a.m., Published: Feb. 3, 2023, midnight
Vulnerabilities: denial of service, format string vulnerability, process crash...
Affected productsExternal IDs

Trust: 5.5

Fetched: Feb. 7, 2023, 9:17 a.m., Published: Feb. 1, 2023, 6:21 a.m.
Vulnerabilities: command injection, code execution
Affected productsExternal IDs
vendor: palo model: networks
vendor: palo alto networks model: networks
vendor: asus model: asus
db: NVD ids: CVE-2021-35394