VARIoT news about IoT security

Trust: 4.0

Fetched: July 22, 2025, 9:55 a.m., Published: July 18, 2025, 3:42 p.m.
Vulnerabilities: privilege escalation, password guessing, code insertion
Affected productsExternal IDs
db: NVD ids: CVE-2025-0282, CVE-2025-22457

Trust: 5.0

Fetched: July 22, 2025, 9:55 a.m., Published: June 26, 2025, 6:58 a.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2025-32877

Trust: 4.25

Fetched: July 22, 2025, 9:54 a.m., Published: July 20, 2025, 5:31 p.m.
Vulnerabilities: command execution, arbitrary command execution
Affected productsExternal IDs
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: snort model: snort
vendor: palo model: networks
vendor: palo model: firewall
db: NVD ids: CVE-2025-0282, CVE-2025-22457

Trust: 4.75

Fetched: July 22, 2025, 9:53 a.m., Published: July 21, 2025, 11:40 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: cisco model: cisco identity services engine
vendor: cisco model: identity services engine
db: NVD ids: CVE-2025-20337

Trust: 4.5

Fetched: July 22, 2025, 9:53 a.m., Published: July 17, 2025, 2:39 a.m.
Vulnerabilities: code execution, file execution
Affected productsExternal IDs
vendor: trend model: security
vendor: trend micro model: security
vendor: cisco model: identity services engine
vendor: cisco model: network access control
db: NVD ids: CVE-2025-20282, CVE-2025-20281, CVE-2025-20337

Trust: 5.75

Fetched: July 22, 2025, 9:53 a.m., Published: July 21, 2025, 6:03 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: cisco model: cisco identity services engine
vendor: cisco model: identity services engine
db: NVD ids: CVE-2025-20337
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132

Trust: 5.0

Fetched: July 22, 2025, 9:52 a.m., Published: June 24, 2025, 5:25 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: fortigate model: fortios
db: NVD ids: CVE-2022-42475

Trust: 3.75

Fetched: July 22, 2025, 9:51 a.m., Published: July 5, 2025, 4:15 a.m.
Vulnerabilities: default credentials
Affected productsExternal IDs

Trust: 4.75

Fetched: July 22, 2025, 9:50 a.m., Published: June 25, 2025, 8 a.m.
Vulnerabilities: default administrator password, authentication bypass, default password...
Affected productsExternal IDs
db: NVD ids: CVE-2024-51978, CVE-2024-51982, CVE-2024-51981, CVE-2024-51983, CVE-2024-51980, CVE-2024-51984, CVE-2024-51977, CVE-2024-51979

Trust: 5.75

Fetched: July 22, 2025, 9:50 a.m., Published: July 14, 2025, 2:31 p.m.
Vulnerabilities: input validation vulnerability
Affected productsExternal IDs
vendor: citrix model: netscaler
vendor: citrix model: netscaler adc
vendor: citrix model: netscaler gateway
vendor: citrix model: gateway
db: NVD ids: CVE-2025-5777

Trust: 5.5

Fetched: July 22, 2025, 9:50 a.m., Published: July 3, 2025, midnight
Vulnerabilities: code execution, privilege escalation, buffer overflow
Affected productsExternal IDs
vendor: lenovo model: updates
vendor: lenovo model: system
vendor: lenovo model: thinkpad
db: NVD ids: CVE-2025-4657

Trust: 5.75

Fetched: July 22, 2025, 9:49 a.m., Published: July 21, 2025, 6:03 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: cisco model: cisco identity services engine
vendor: cisco model: identity services engine
db: NVD ids: CVE-2025-20337

Trust: 3.75

Fetched: July 22, 2025, 9:49 a.m., Published: July 18, 2025, 9:46 a.m.
Vulnerabilities: default credentials
Affected productsExternal IDs

Trust: 4.75

Fetched: July 22, 2025, 9:48 a.m., Published: July 16, 2025, 3:57 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: cisco model: cisco identity services engine
vendor: cisco model: identity services engine
db: NVD ids: CVE-2025-20284, CVE-2025-20283, CVE-2025-20285
Related entries in the VARIoT vulnerabilities database: VAR-202205-1364

Trust: 4.5

Fetched: July 22, 2025, 9:43 a.m., Published: July 20, 2025, 5:26 p.m.
Vulnerabilities: code execution, privilege escalation, path traversal
Affected productsExternal IDs
db: NVD ids: CVE-2022-26694

Trust: 5.0

Fetched: July 22, 2025, 9:42 a.m., Published: July 19, 2025, 3:19 a.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
db: NVD ids: CVE-2025-25257

Trust: 4.5

Fetched: July 22, 2025, 9:42 a.m., Published: July 17, 2025, midnight
Vulnerabilities: code execution, privilege escalation
Affected productsExternal IDs
vendor: sophos model: intercept x endpoint
db: NVD ids: CVE-2025-7433, CVE-2024-13972, CVE-2025-7472

Trust: 3.25

Fetched: July 22, 2025, 9:40 a.m., Published: July 21, 2025, 6:45 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 4.5

Fetched: July 22, 2025, 9:40 a.m., Published: July 21, 2025, 8:26 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: google model: google chrome
vendor: google model: chrome
vendor: google model: android
vendor: apple model: macos
db: NVD ids: CVE-2025-6558, CVE-2025-6554, CVE-2025-6556, CVE-2025-6555, CVE-2025-6559

Trust: 5.0

Fetched: July 22, 2025, 9:38 a.m., Published: July 18, 2025, 12:42 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: ubiquiti model: unifi
db: NVD ids: CVE-2025-27212