VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202202-1707, VAR-202203-0043

Trust: 5.5

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 2050, midnight
Vulnerabilities: buffer overflow, privilege escalation, memory corruption...
Affected productsExternal IDs
vendor: alsa model: alsa
db: NVD ids: CVE-2022-0617, CVE-2022-0998, CVE-2022-0646, CVE-2022-26966, CVE-2022-1280, CVE-2022-26490, CVE-2022-1516, CVE-2022-0435, CVE-2022-27223, CVE-2022-28893, CVE-2022-25375, CVE-2022-0494, CVE-2022-0516, CVE-2022-29968, CVE-2022-1015, CVE-2022-0487, CVE-2022-1116, CVE-2022-24448, CVE-2022-24122, CVE-2022-23222, CVE-2022-1353, CVE-2022-0433, CVE-2022-27950, CVE-2022-25265, CVE-2022-0500, CVE-2022-27666, CVE-2022-26878, CVE-2022-25258, CVE-2022-1195, CVE-2022-29582, CVE-2022-0995, CVE-2022-24958, CVE-2022-30594, CVE-2022-0854, CVE-2022-25636, CVE-2022-28388, CVE-2022-0492, CVE-2022-28356, CVE-2022-1679, CVE-2022-1048, CVE-2022-29581, CVE-2022-1055, CVE-2022-0847, CVE-2022-1011, CVE-2022-29156, CVE-2022-28390, CVE-2022-24959, CVE-2022-28796, CVE-2022-0742, CVE-2022-28389

Trust: 6.25

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 2050, midnight
Vulnerabilities: cross-site scripting, code execution, denial of service...
Affected productsExternal IDs
vendor: clam model: clamav
vendor: cisco model: cisco ios
vendor: cisco model: adaptive security appliance
vendor: cisco model: cisco sd-wan
vendor: cisco model: webex
vendor: cisco model: unity connection
vendor: cisco model: cisco firepower management center
vendor: cisco model: ios xr
vendor: cisco model: cisco unity
vendor: cisco model: expressway series
vendor: cisco model: ios xr software
vendor: cisco model: cisco webex
vendor: cisco model: firepower threat defense
vendor: cisco model: cisco ios xr
vendor: cisco model: security manager
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: wireless access point
vendor: cisco model: sd-wan vmanage software
vendor: cisco model: sd-wan
vendor: cisco model: telepresence
vendor: cisco model: staros
vendor: cisco model: asdm
vendor: cisco model: cisco security manager
vendor: cisco model: clientless ssl vpn
vendor: cisco model: device manager
vendor: cisco model: cisco expressway
vendor: cisco model: series
vendor: cisco model: firepower management center
vendor: cisco model: umbrella virtual appliance
vendor: cisco model: umbrella
vendor: cisco model: cisco webex meetings
vendor: cisco model: security device manager
vendor: cisco model: cisco staros
vendor: cisco model: unified communications manager session management edition
vendor: cisco model: webex meetings
vendor: cisco model: sd-wan vmanage
vendor: cisco model: cisco roomos
vendor: cisco model: router
vendor: cisco model: firepower
vendor: cisco model: roomos
vendor: cisco model: unity
vendor: cisco model: cisco unified communications manager
vendor: cisco model: telepresence collaboration endpoint
vendor: cisco model: identity services engine
vendor: cisco model: adaptive security device manager
vendor: cisco model: telepresence video communication server
vendor: cisco model: clamav
vendor: cisco model: cisco telepresence
vendor: cisco model: cisco unity connection
vendor: cisco model: unified communications manager
vendor: cisco model: cisco telepresence video communication server
vendor: cisco model: 1000 series connected grid router
vendor: cisco model: cisco umbrella virtual appliance
vendor: cisco model: cgr1k
vendor: cisco model: cisco identity services engine
vendor: cisco model: expressway
vendor: cisco model: unified communications
vendor: clamav model: clamav
vendor: snort model: snort
db: NVD ids: CVE-2022-20737, CVE-2022-20770, CVE-2022-20787, CVE-2022-20804, CVE-2022-20745, CVE-2022-20738, CVE-2022-20750, CVE-2022-20756, CVE-2022-22965, CVE-2022-20796, CVE-2022-20788, CVE-2022-20779, CVE-2022-20743, CVE-2022-20746, CVE-2022-20742, CVE-2022-20730, CVE-2022-20729, CVE-2022-20794, CVE-2022-20767, CVE-2022-20741, CVE-2022-20786, CVE-2022-20789, CVE-2022-20755, CVE-2022-20782, CVE-2022-20740, CVE-2022-20739, CVE-2022-20760, CVE-2022-20763, CVE-2022-20780, CVE-2022-20732, CVE-2022-20777, CVE-2022-20764, CVE-2022-20758, CVE-2022-20790, CVE-2022-20735, CVE-2022-20773, CVE-2022-20748, CVE-2022-20783, CVE-2022-20771, CVE-2022-20759, CVE-2022-20747, CVE-2022-20734, CVE-2022-20762, CVE-2022-20761, CVE-2022-20778, CVE-2022-20757, CVE-2022-20785, CVE-2022-20744, CVE-2022-20754, CVE-2022-20805

Trust: 6.25

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 2050, midnight
Vulnerabilities: cross-site scripting, code execution, denial of service...
Affected productsExternal IDs
vendor: clam model: clamav
vendor: cisco model: cisco ios
vendor: cisco model: adaptive security appliance
vendor: cisco model: cisco sd-wan
vendor: cisco model: webex
vendor: cisco model: unity connection
vendor: cisco model: cisco firepower management center
vendor: cisco model: ios xr
vendor: cisco model: cisco unity
vendor: cisco model: expressway series
vendor: cisco model: ios xr software
vendor: cisco model: cisco webex
vendor: cisco model: firepower threat defense
vendor: cisco model: cisco ios xr
vendor: cisco model: security manager
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: wireless access point
vendor: cisco model: sd-wan vmanage software
vendor: cisco model: sd-wan
vendor: cisco model: telepresence
vendor: cisco model: staros
vendor: cisco model: asdm
vendor: cisco model: cisco security manager
vendor: cisco model: clientless ssl vpn
vendor: cisco model: device manager
vendor: cisco model: cisco expressway
vendor: cisco model: series
vendor: cisco model: firepower management center
vendor: cisco model: umbrella virtual appliance
vendor: cisco model: umbrella
vendor: cisco model: cisco webex meetings
vendor: cisco model: security device manager
vendor: cisco model: cisco staros
vendor: cisco model: unified communications manager session management edition
vendor: cisco model: webex meetings
vendor: cisco model: sd-wan vmanage
vendor: cisco model: cisco roomos
vendor: cisco model: router
vendor: cisco model: firepower
vendor: cisco model: roomos
vendor: cisco model: unity
vendor: cisco model: cisco unified communications manager
vendor: cisco model: telepresence collaboration endpoint
vendor: cisco model: identity services engine
vendor: cisco model: adaptive security device manager
vendor: cisco model: telepresence video communication server
vendor: cisco model: clamav
vendor: cisco model: cisco telepresence
vendor: cisco model: cisco unity connection
vendor: cisco model: unified communications manager
vendor: cisco model: cisco telepresence video communication server
vendor: cisco model: 1000 series connected grid router
vendor: cisco model: cisco umbrella virtual appliance
vendor: cisco model: cgr1k
vendor: cisco model: cisco identity services engine
vendor: cisco model: expressway
vendor: cisco model: unified communications
vendor: clamav model: clamav
vendor: snort model: snort
db: NVD ids: CVE-2022-20737, CVE-2022-20770, CVE-2022-20787, CVE-2022-20804, CVE-2022-20745, CVE-2022-20738, CVE-2022-20750, CVE-2022-20756, CVE-2022-22965, CVE-2022-20796, CVE-2022-20788, CVE-2022-20779, CVE-2022-20743, CVE-2022-20746, CVE-2022-20742, CVE-2022-20730, CVE-2022-20729, CVE-2022-20794, CVE-2022-20767, CVE-2022-20741, CVE-2022-20786, CVE-2022-20789, CVE-2022-20755, CVE-2022-20782, CVE-2022-20740, CVE-2022-20739, CVE-2022-20760, CVE-2022-20763, CVE-2022-20780, CVE-2022-20732, CVE-2022-20777, CVE-2022-20764, CVE-2022-20758, CVE-2022-20790, CVE-2022-20735, CVE-2022-20773, CVE-2022-20748, CVE-2022-20783, CVE-2022-20771, CVE-2022-20759, CVE-2022-20747, CVE-2022-20734, CVE-2022-20762, CVE-2022-20761, CVE-2022-20778, CVE-2022-20757, CVE-2022-20785, CVE-2022-20744, CVE-2022-20754, CVE-2022-20805

Trust: 3.5

Fetched: June 1, 2022, 8:16 a.m., Published: April 20, 2022, 3:10 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lenovo model: updates
vendor: lenovo model: notebook
vendor: lenovo model: bios
vendor: lenovo model: system
vendor: lenovo model: flex
vendor: lenovo model: yoga
db: NVD ids: CVE-2021-3972, CVE-2021-3971, CVE-2021-3970

Trust: 6.25

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 2050, midnight
Vulnerabilities: improper validation, kernel panic, denial of service...
Affected productsExternal IDs
vendor: clam model: clamav
vendor: cisco model: cisco ios
vendor: cisco model: adaptive security appliance
vendor: cisco model: ios xr
vendor: cisco model: ios xr software
vendor: cisco model: cisco ios xe
vendor: cisco model: firepower threat defense
vendor: cisco model: cisco ios xr
vendor: cisco model: cisco email security appliance
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: wireless access point
vendor: cisco model: ios xe software
vendor: cisco model: telepresence
vendor: cisco model: staros
vendor: cisco model: clientless ssl vpn
vendor: cisco model: series
vendor: cisco model: catalyst 9800
vendor: cisco model: ios software
vendor: cisco model: ios xe
vendor: cisco model: catalyst
vendor: cisco model: asyncos software
vendor: cisco model: series wireless controllers
vendor: cisco model: wireless controller
vendor: cisco model: cisco staros
vendor: cisco model: unified communications manager session management edition
vendor: cisco model: cisco roomos
vendor: cisco model: asyncos
vendor: cisco model: router
vendor: cisco model: firepower
vendor: cisco model: email security appliance
vendor: cisco model: roomos
vendor: cisco model: cisco unified communications manager
vendor: cisco model: telepresence collaboration endpoint
vendor: cisco model: access points
vendor: cisco model: cisco asyncos
vendor: cisco model: clamav
vendor: cisco model: cisco telepresence
vendor: cisco model: unified communications manager
vendor: cisco model: 1000 series connected grid router
vendor: cisco model: cgr1k
vendor: cisco model: unified communications
vendor: clamav model: clamav
vendor: snort model: snort
db: NVD ids: CVE-2022-20737, CVE-2022-20694, CVE-2022-20770, CVE-2022-20653, CVE-2022-20804, CVE-2022-20745, CVE-2022-20715, CVE-2022-20692, CVE-2022-20750, CVE-2022-20697, CVE-2022-20796, CVE-2022-20683, CVE-2022-20746, CVE-2022-20682, CVE-2022-20794, CVE-2022-20767, CVE-2021-34704, CVE-2022-20760, CVE-2022-20764, CVE-2022-20758, CVE-2022-20679, CVE-2022-20622, CVE-2022-20748, CVE-2022-20783, CVE-2022-20771, CVE-2022-20684, CVE-2022-20761, CVE-2022-20757, CVE-2022-20785, CVE-2021-1573

Trust: 4.5

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 6002, midnight
Vulnerabilities: command execution, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2022-27224
Related entries in the VARIoT vulnerabilities database: VAR-202203-1409, VAR-202203-0870, VAR-202203-0835, VAR-202203-0836

Trust: 4.0

Fetched: June 1, 2022, 8:16 a.m., Published: March 4, 2022, 6:10 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: cisco expressway
vendor: cisco model: series
vendor: cisco model: cisco telepresence video communication server
vendor: cisco model: small business
vendor: cisco model: catalyst 4500
vendor: cisco model: rv260
vendor: cisco model: rv340
vendor: cisco model: rv325 dual gigabit wan vpn
vendor: cisco model: ios xe
vendor: cisco model: series switches
vendor: cisco model: catalyst
vendor: cisco model: expressway series
vendor: cisco model: rv345
vendor: cisco model: expressway
vendor: cisco model: cisco staros
vendor: cisco model: rv320
vendor: cisco model: identity services engine
vendor: cisco model: telepresence video communication server
vendor: cisco model: rv160
vendor: cisco model: telepresence
vendor: cisco model: staros
vendor: cisco model: cisco telepresence
vendor: cisco model: rv325
db: NVD ids: CVE-2022-20762, CVE-2022-20665, CVE-2022-20756, CVE-2022-20754, CVE-2022-20755

Trust: 3.0

Fetched: June 1, 2022, 8:16 a.m., Published: May 19, 2022, 9:42 a.m.
Vulnerabilities: -
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202107-1010

Trust: 3.75

Fetched: June 1, 2022, 8:16 a.m., Published: March 17, 2022, 2:41 a.m.
Vulnerabilities: password guessing
Affected productsExternal IDs
db: NVD ids: CVE-2021-34527

Trust: 4.5

Fetched: June 1, 2022, 8:16 a.m., Published: -
Vulnerabilities: code execution, format string vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2022-1215
Related entries in the VARIoT vulnerabilities database: VAR-202205-0957

Trust: 3.75

Fetched: June 1, 2022, 8:16 a.m., Published: June 1, 2022, midnight
Vulnerabilities: code execution, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2022-30525
Related entries in the VARIoT vulnerabilities database: VAR-202203-0043

Trust: 4.75

Fetched: June 1, 2022, 8:16 a.m., Published: March 16, 2022, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: google model: android
vendor: google model: pixel
vendor: samsung model: samsung
db: NVD ids: CVE-2022-0847
Related entries in the VARIoT vulnerabilities database: VAR-202105-1166

Trust: 5.75

Fetched: June 1, 2022, 8:16 a.m., Published: April 29, 2022, 9:48 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: synology model: diskstation
vendor: synology model: diskstation manager
vendor: synology model: synology router manager
vendor: synology model: router manager
vendor: trend micro model: security
vendor: netbsd model: netbsd
vendor: trend model: security
vendor: netatalk model: netatalk
db: NVD ids: CVE-2022-23125, CVE-2022-23123, CVE-2021-31439, CVE-2022-23121, CVE-2022-23124, CVE-2022-23122, CVE-2022-0194
Related entries in the VARIoT vulnerabilities database: VAR-202205-0394

Trust: 3.75

Fetched: June 1, 2022, 8:16 a.m., Published: June 2, 2022, midnight
Vulnerabilities: code execution, privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2022-22972, CVE-2022-22954, CVE-2022-22973, CVE-2022-22960, CVE-2022-1388

Trust: 3.75

Fetched: June 1, 2022, 8:16 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: lenovo model: l340-15iwl
vendor: lenovo model: l340-15irh
vendor: lenovo model: l340-17irh
vendor: lenovo model: bios
vendor: lenovo model: notebook
vendor: lenovo model: l340-17iwl
vendor: lenovo model: yoga
db: NVD ids: CVE-2021-3972, CVE-2021-3971, CVE-2021-3970

Trust: 3.0

Fetched: June 1, 2022, 8:16 a.m., Published: April 20, 2022, 9 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lenovo model: desktop

Trust: 3.0

Fetched: June 1, 2022, 8:16 a.m., Published: May 17, 2022, 7:20 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: iphone

Trust: 5.0

Fetched: June 1, 2022, 8:16 a.m., Published: May 25, 2022, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: google chrome
vendor: google model: chrome
Related entries in the VARIoT vulnerabilities database: VAR-202203-0237

Trust: 5.25

Fetched: June 1, 2022, 8:16 a.m., Published: May 3, 2022, 11:07 a.m.
Vulnerabilities: code execution, memory corruption
Affected productsExternal IDs
vendor: aruba model: web management portal
vendor: extremenetworks model: ers3500
db: NVD ids: CVE-2022-29861, CVE-2022-29860, CVE-2022-22805, CVE-2022-23677, CVE-2022-23676
Related entries in the VARIoT vulnerabilities database: VAR-202203-1506

Trust: 3.5

Fetched: June 1, 2022, 8:16 a.m., Published: March 31, 2022, 10:09 p.m.
Vulnerabilities: code execution, denial of service, information exposure
Affected productsExternal IDs
db: NVD ids: CVE-2022-22950, CVE-2022-22965, CVE-2022-22695, CVE-2022-22963