VARIoT news about IoT security

Trust: 3.0

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 30, 2021, 1:17 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 5.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 10, 2021, 4:15 p.m.
Vulnerabilities: input validation error, path traversal, authentication bypass...
Affected productsExternal IDs
vendor: google model: android
vendor: google model: chrome
vendor: google model: google chrome
vendor: check point model: check point
vendor: d-link model: router
vendor: dasan model: gpon router
vendor: dasan model: gpon routers
db: NVD ids: CVE-2020-5410, CVE-2014-0160, CVE-2015-7254, CVE-2020-13756, CVE-2017-11512, CVE-2016-4523, CVE-2010-4598, CVE-2020-10828, CVE-2013-6719, CVE-2019-18952, CVE-2016-8530, CVE-2020-8260, CVE-2017-5638, CVE-2021-42013, CVE-2013-6720, CVE-2021-41773, CVE-2014-0780, CVE-2020-10826, CVE-2019-0230, CVE-2020-10827, CVE-2015-2051, CVE-2018-3948, CVE-2014-0346, CVE-2014-0130, CVE-2015-4068, CVE-2018-10561, CVE-2018-3949, CVE-2011-2474, CVE-2015-0666

Trust: 3.75

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Jan. 5, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: vivo model: vivo
vendor: check point model: check point
db: NVD ids: CVE-2021-0662, CVE-2021-0661, CVE-2021-0663, CVE-2021-0673
Related entries in the VARIoT vulnerabilities database: VAR-202109-1802

Trust: 3.75

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 12, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: hitachi model: infrastructure analytics advisor
vendor: hitachi model: hitachi infrastructure analytics advisor
vendor: hitachi model: hitachi device manager
vendor: hitachi model: device manager
db: NVD ids: CVE-2021-40438

Trust: 4.25

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Dec. 2, 2021, 2 p.m.
Vulnerabilities: file upload vulnerability, code execution
Affected productsExternal IDs
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo model: palo alto networks
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
vendor: palo alto networks model: palo alto networks
vendor: paloaltonetworks model: networks
vendor: paloaltonetworks model: firewall
vendor: paloaltonetworks model: palo alto networks
vendor: zoho model: manageengine adselfservice plus
vendor: zoho model: manageengine servicedesk plus
db: NVD ids: CVE-2021-37415, CVE-2021-33617, CVE-2021-44077

Trust: 5.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 16, 2021, midnight
Vulnerabilities: code execution, security feature bypass, feature bypass
Affected productsExternal IDs
vendor: trend micro model: security
vendor: trend model: security
db: NVD ids: CVE-2021-42292, CVE-2021-38631, CVE-2021-38666, CVE-2021-42321, CVE-2021-41371

Trust: 3.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 10, 2021, 4:11 p.m.
Vulnerabilities: security feature bypass, code execution, feature bypass...
Affected productsExternal IDs
db: NVD ids: CVE-2021-38631, CVE-2021-42279, CVE-2021-41371, CVE-2021-42316, CVE-2021-26443, CVE-2021-42296, CVE-2021-43209, CVE-2021-41351, CVE-2021-42321, CVE-2021-42298, CVE-2021-42292, CVE-2021-3711, CVE-2021-38666, CVE-2021-42285, CVE-2021-43208

Trust: 4.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Dec. 6, 2021, 10 a.m.
Vulnerabilities: sql injection, os command injection, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2017-0144

Trust: 4.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Oct. 7, 2021, 3:34 a.m.
Vulnerabilities: authentication attack, code execution, injection attack...
Affected productsExternal IDs
vendor: trend model: security

Trust: 3.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Jan. 15, 2022, 6:44 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: home

Trust: 4.25

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Dec. 4, 2021, 12:04 p.m.
Vulnerabilities: buffer overflow
Affected productsExternal IDs

Trust: 4.25

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Jan. 8, 2022, midnight
Vulnerabilities: os command injection, command injection
Affected productsExternal IDs
db: NVD ids: CVE-2021-3577

Trust: 3.75

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 10, 2021, 7:53 a.m.
Vulnerabilities: code execution, security feature bypass, feature bypass
Affected productsExternal IDs

Trust: 3.0

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Nov. 24, 2021, 10:33 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 6.0

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Dec. 28, 2021, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: access points
vendor: cisco model: catalyst
vendor: cisco model: cisco ios
vendor: cisco model: ios xe software
vendor: cisco model: ios xe
vendor: cisco model: cisco ios xe
db: NVD ids: CVE-2021-34768

Trust: 3.75

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Dec. 28, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: cisco model: cisco anyconnect secure mobility client
vendor: cisco model: series
vendor: cisco model: anyconnect secure mobility client
db: NVD ids: CVE-2021-34788

Trust: 3.5

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Jan. 10, 2022, midnight
Vulnerabilities: integer overflow
Affected productsExternal IDs
vendor: cisco systems model: cisco systems
vendor: cisco model: cisco systems
vendor: blackberry model: smartphone
vendor: blackberry model: blackberry
vendor: google model: wifi
vendor: google model: android
Related entries in the VARIoT vulnerabilities database: VAR-202109-1910

Trust: 3.75

Fetched: Dec. 7, 2021, 8:04 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: siemens model: simatic
vendor: siemens model: simatic net
db: SIEMENS ids: SSA-549234
Related entries in the VARIoT vulnerabilities database: VAR-202109-1918

Trust: 3.0

Fetched: Dec. 7, 2021, 8:04 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
db: SIEMENS ids: SSA-500748
Related entries in the VARIoT vulnerabilities database: VAR-202104-1963, VAR-202104-1960

Trust: 5.25

Fetched: Dec. 7, 2021, 8:04 a.m., Published: Jan. 1, 2022, midnight
Vulnerabilities: buffer overflow, code execution, memory corruption...
Affected productsExternal IDs
vendor: cesanta model: mongoose
vendor: cesanta model: mongoose os
vendor: riot model: riot
vendor: samsung model: samsung
vendor: blackberry model: blackberry
vendor: blackberry model: link
vendor: windriver model: river vxworks
vendor: windriver model: vxworks
vendor: mbed model: mbed
db: NVD ids: CVE-2020-35198, CVE-2021-27429, CVE-2021-27433, CVE-2021-27419, CVE-2021-27427, CVE-2021-27417, CVE-2021-22684, CVE-2021-26706, CVE-2021-22156, CVE-2021-27421, CVE-2021-27411, CVE-2021-3420, CVE-2021-30636, CVE-2021-27425, CVE-2020-28895, CVE-2021-26461, CVE-2021-22636, CVE-2021-27504, CVE-2021-31571, CVE-2021-31572, CVE-2021-27435, CVE-2020-13603, CVE-2021-27431, CVE-2021-22680, CVE-2021-27439, CVE-2021-27502