VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202210-0198

Trust: 4.0

Fetched: Jan. 10, 2023, 9:11 a.m., Published: Jan. 5, 2023, 6 p.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2022-40684

Trust: 4.5

Fetched: Jan. 10, 2023, 9:10 a.m., Published: Nov. 17, 2022, 11:48 p.m.
Vulnerabilities: policy violation, script execution
Affected productsExternal IDs
vendor: essential model: phone

Trust: 3.0

Fetched: Jan. 8, 2023, 9:17 a.m., Published: Jan. 8, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: pixel

Trust: 3.25

Fetched: Jan. 8, 2023, 9:16 a.m., Published: Jan. 30, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: netgear model: router

Trust: 3.25

Fetched: Jan. 8, 2023, 9:15 a.m., Published: Dec. 30, 2022, 1:02 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: netgear model: router

Trust: 3.75

Fetched: Jan. 8, 2023, 9:15 a.m., Published: Jan. 5, 2023, 5:01 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: trend model: security

Trust: 3.5

Fetched: Jan. 8, 2023, 9:15 a.m., Published: Dec. 30, 2022, 11:30 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: google home
vendor: google model: android
vendor: google model: home

Trust: 3.75

Fetched: Jan. 8, 2023, 9:14 a.m., Published: Jan. 4, 2023, 1:14 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: samsung model: knox
vendor: samsung model: note
vendor: samsung model: galaxy
vendor: samsung model: note 10
vendor: samsung model: galaxy note
vendor: google model: android

Trust: 3.0

Fetched: Jan. 8, 2023, 9:13 a.m., Published: Jan. 4, 2023, 12:32 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lenovo model: thinkpad
vendor: lenovo model: bios

Trust: 3.5

Fetched: Jan. 8, 2023, 9:13 a.m., Published: April 15, 2021, 4 p.m.
Vulnerabilities: denial of service, code execution
Affected productsExternal IDs

Trust: 3.75

Fetched: Jan. 8, 2023, 9:12 a.m., Published: Jan. 5, 2023, midnight
Vulnerabilities: sql injection
Affected productsExternal IDs

Trust: 3.75

Fetched: Jan. 6, 2023, 9:19 a.m., Published: Dec. 29, 2022, 6:55 p.m.
Vulnerabilities: denial of service, buffer overflow, code execution
Affected productsExternal IDs
vendor: netgear model: netgear router
vendor: netgear model: orbi
vendor: netgear model: rax40
vendor: netgear model: rax35
vendor: netgear model: router
vendor: netgear model: r7000p
vendor: netgear model: r8000p firmware
vendor: netgear model: r6700v3
vendor: netgear model: rax40 firmware
vendor: netgear model: r7000p firmware
vendor: netgear model: r8000p
vendor: netgear model: r6400v2
vendor: netgear model: r6900p
vendor: netgear model: r6900p firmware

Trust: 3.75

Fetched: Jan. 6, 2023, 9:19 a.m., Published: Dec. 6, 2023, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: samsung model: note
vendor: samsung model: mobile
vendor: samsung model: galaxy
vendor: samsung model: samsung galaxy
vendor: comcast model: xfinity
Related entries in the VARIoT vulnerabilities database: VAR-202212-1132

Trust: 3.25

Fetched: Jan. 6, 2023, 9:17 a.m., Published: June 16, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2022-42475
Related entries in the VARIoT vulnerabilities database: VAR-202301-0628, VAR-202301-0582, VAR-202301-0521

Trust: 3.75

Fetched: Jan. 6, 2023, 9:17 a.m., Published: Jan. 5, 2023, 1:36 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: lenovo model: bios
vendor: lenovo model: thinkpad
vendor: lenovo model: updates
db: NVD ids: CVE-2022-33218, CVE-2022-33219, CVE-2022-33265, CVE-2022-40516, CVE-2022-40520

Trust: 5.0

Fetched: Jan. 6, 2023, 9:16 a.m., Published: Jan. 4, 2023, midnight
Vulnerabilities: command injection
Affected productsExternal IDs
vendor: brocade model: fabric os
vendor: brocade model: brocade fabric os

Trust: 3.5

Fetched: Jan. 6, 2023, 9:15 a.m., Published: Dec. 25, 2022, midnight
Vulnerabilities: cross-site scripting, sql injection, weak password
Affected productsExternal IDs
vendor: sophos model: firewall
vendor: cisco model: routers
vendor: cisco model: guard
vendor: cisco model: umbrella

Trust: 3.0

Fetched: Jan. 6, 2023, 9:15 a.m., Published: Jan. 2, 2023, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
Related entries in the VARIoT vulnerabilities database: VAR-202301-0249

Trust: 4.75

Fetched: Jan. 6, 2023, 9:14 a.m., Published: Jan. 6, 2023, midnight
Vulnerabilities: memory corruption, buffer overflow, code execution
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2022-42720, CVE-2022-42721, CVE-2022-42719, CVE-2022-22088, CVE-2022-41674

Trust: 5.5

Fetched: Jan. 6, 2023, 9:13 a.m., Published: -
Vulnerabilities: privilege escalation, information disclosure, code execution
Affected productsExternal IDs
vendor: google model: pixel
vendor: google model: android
db: NVD ids: CVE-2022-20411, CVE-2022-20472, CVE-2022-20473, CVE-2022-20498