VARIoT news about IoT security

Trust: 3.5

Fetched: Dec. 16, 2021, 8:11 p.m., Published: March 16, 2021, midnight
Vulnerabilities: sql injection
Affected productsExternal IDs
vendor: google model: chrome
vendor: google model: google chrome
vendor: trend model: security

Trust: 4.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Nov. 19, 2021, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-21972, CVE-2021-21973
db: VMWARE ids: VMSA-2021-0002
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566

Trust: 4.25

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 12, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: huawei model: huawei
db: NVD ids: CVE-2021-44228

Trust: 3.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 8, 2021, 2:52 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 5.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Nov. 24, 2021, 4:29 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: xiaomi model: miui
vendor: xiaomi model: redmi
vendor: vivo model: vivo
vendor: check point model: check point
db: NVD ids: CVE-2021-0662, CVE-2021-0661, CVE-2021-0663, CVE-2021-0673

Trust: 5.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 8, 2021, 6:57 p.m.
Vulnerabilities: command injection, buffer overflow, path traversal...
Affected productsExternal IDs
vendor: sonicwall model: sma 100
db: NVD ids: CVE-2021-20038, CVE-2021-20043, CVE-2021-20044, CVE-2021-20045, CVE-2021-20039, CVE-2021-20040, CVE-2021-20041, CVE-2021-20042

Trust: 3.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: -
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2021-39238

Trust: 5.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Jan. 7, 2022, 7:33 p.m.
Vulnerabilities: code execution, authentication vulnerability, file upload vulnerability...
Affected productsExternal IDs
db: NVD ids: CVE-2021-43936, CVE-2021-43931
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566

Trust: 4.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 11, 2021, 4:18 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-44228
Related entries in the VARIoT vulnerabilities database: VAR-201907-1641, VAR-202112-1044, VAR-201712-0864, VAR-202112-0566

Trust: 4.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 24, 2021, midnight
Vulnerabilities: authentication bypass, access control vulnerability, privilege management vulnerability...
Affected productsExternal IDs
vendor: embedthis model: goahead
db: NVD ids: CVE-2019-13272, CVE-2021-44168, CVE-2017-17562, CVE-2020-8816, CVE-2021-35394, CVE-2019-0193, CVE-2019-10758, CVE-2010-1871, CVE-2021-44228, CVE-2019-7238, CVE-2021-44515, CVE-2020-17463, CVE-2017-12149

Trust: 3.5

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 12, 2021, 5:21 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: samsung model: galaxy
vendor: samsung model: knox
vendor: samsung model: samsung
vendor: samsung model: mobile

Trust: 3.5

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Nov. 18, 2021, 2 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: huawei model: huawei

Trust: 3.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 23, 2021, 8:32 a.m.
Vulnerabilities: password management vulnerability
Affected productsExternal IDs
db: NVD ids: CVE-2021-35033

Trust: 4.5

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 3, 2021, 10:34 a.m.
Vulnerabilities: authentication bypass
Affected productsExternal IDs
vendor: palo alto networks model: palo alto networks
vendor: palo alto networks model: networks
vendor: zoho model: manageengine servicedesk plus
vendor: palo model: palo alto networks
vendor: palo model: networks
db: NVD ids: CVE-2021-33617, CVE-2021-44077

Trust: 3.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 8, 2021, midnight
Vulnerabilities: cross-site scripting
Affected productsExternal IDs
vendor: trend model: security

Trust: 4.75

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 9, 2021, 1:52 p.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
vendor: sonicwall model: sma 100
vendor: sonicwall model: secure mobile access

Trust: 4.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 11, 2021, 5:27 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: icloud

Trust: 5.25

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 1, 2021, 5:01 a.m.
Vulnerabilities: buffer overflow, code execution
Affected productsExternal IDs
vendor: dram model: dram
vendor: palo model: networks
vendor: palo model: pan-os
vendor: palo model: firewall
vendor: palo model: palo alto networks
vendor: palo alto networks model: networks
vendor: palo alto networks model: pan-os
vendor: palo alto networks model: firewall
vendor: palo alto networks model: palo alto networks
vendor: unbound model: unbound
vendor: dnsmasq model: dnsmasq
db: NVD ids: CVE-2021-3064, CVE-2021-42114, CVE-2021-20322
Related entries in the VARIoT vulnerabilities database: VAR-202112-1782, VAR-202112-0566, VAR-202112-0562

Trust: 4.5

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 15, 2021, 8:35 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: palo model: palo alto networks
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo alto networks model: palo alto networks
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
db: NVD ids: CVE-2021-45105, CVE-2021-44228, CVE-2021-45046
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566

Trust: 4.0

Fetched: Dec. 16, 2021, 8:11 p.m., Published: Dec. 10, 2021, 11:39 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2021-44228