VARIoT news about IoT security

Related entries in the VARIoT vulnerabilities database: VAR-202210-0815, VAR-202210-0792, VAR-202210-1013, VAR-202210-0849, VAR-202210-0898, VAR-202210-0918

Trust: 4.0

Fetched: Nov. 8, 2022, 10:13 a.m., Published: Nov. 1, 2022, 10:43 a.m.
Vulnerabilities: file inclusion, code execution, path traversal...
Affected productsExternal IDs
db: NVD ids: CVE-2022-22243, CVE-2022-22244, CVE-2022-22241, CVE-2022-22245, CVE-2022-22246, CVE-2022-22242

Trust: 5.0

Fetched: Nov. 8, 2022, 10:12 a.m., Published: Nov. 1, 2022, 10:15 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: google model: android
vendor: google model: google chrome
vendor: google model: chrome

Trust: 4.25

Fetched: Nov. 8, 2022, 10:10 a.m., Published: -
Vulnerabilities: information disclosure, request forgery, code execution...
Affected productsExternal IDs
vendor: typo3 model: typo3
vendor: axis model: m1125
vendor: axis model: communications
vendor: delta model: diaenergie
vendor: hitachi vantara model: pentaho business analytics
vendor: hitachi vantara model: pentaho
vendor: automationdirect model: c-more
vendor: fiberhome model: routers
vendor: fiberhome model: router
vendor: moxa model: mxview
vendor: hitachi model: web server
vendor: hitachi model: vantara pentaho
vendor: samsung model: note
vendor: samsung model: mobile
vendor: tp-link model: wr841n
vendor: tp-link model: tl-wr841n
vendor: tp-link model: routers
vendor: tp-link model: tp-link tl-wr841n
vendor: netgear model: r8000
vendor: netgear model: r6400v2
vendor: netgear model: r6700v3
vendor: netgear model: r6900
vendor: netgear model: r6900p
vendor: netgear model: rs400
vendor: netgear model: r7850
vendor: netgear model: r6700
vendor: netgear model: r7000p
vendor: netgear model: router
vendor: netgear model: r7000
vendor: netgear model: r7900
vendor: delta electronics model: diaenergie
vendor: trend model: security
vendor: node.js model: node.js
db: NVD ids: CVE-2022-32245, CVE-2022-31204, CVE-2022-39287, CVE-2022-31046, CVE-2022-30993, CVE-2022-27619, CVE-2022-2003, CVE-2021-45104, CVE-2022-28861, CVE-2022-1524, CVE-2022-30994, CVE-2021-45735, CVE-2022-20243, CVE-2021-40392, CVE-2021-40366, CVE-2022-23105, CVE-2021-41835, CVE-2021-39882, CVE-2021-45447, CVE-2021-42948, CVE-2022-21829, CVE-2022-42916, CVE-2022-29874, CVE-2022-0988, CVE-2022-2005, CVE-2021-41849, CVE-2022-30312, CVE-2021-39272, CVE-2022-39269, CVE-2022-41636, CVE-2021-40846, CVE-2022-34371, CVE-2022-21798, CVE-2022-29519, CVE-2021-44518, CVE-2022-29733, CVE-2022-2485, CVE-2021-40847, CVE-2022-25805, CVE-2022-2338, CVE-2022-33724, CVE-2022-0162, CVE-2021-45894, CVE-2022-41983, CVE-2021-45100, CVE-2022-30115, CVE-2022-26077, CVE-2022-38846, CVE-2022-36200, CVE-2021-42699

Trust: 3.0

Fetched: Nov. 8, 2022, 10:09 a.m., Published: Nov. 3, 2022, 8:09 a.m.
Vulnerabilities: code execution, buffer overflow
Affected productsExternal IDs
db: NVD ids: CVE-2022-3786, CVE-2022-3602

Trust: 4.75

Fetched: Nov. 8, 2022, 10:07 a.m., Published: Feb. 5, 2001, midnight
Vulnerabilities: replay attack, authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2022-42731

Trust: 3.0

Fetched: Nov. 8, 2022, 10 a.m., Published: Aug. 19, 2022, 9:04 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: macos
vendor: apple model: safari

Trust: 3.0

Fetched: Nov. 8, 2022, 9:59 a.m., Published: Oct. 19, 2022, 9:04 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2019-0608

Trust: 3.0

Fetched: Nov. 8, 2022, 9:59 a.m., Published: Nov. 15, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: webkit
vendor: apple model: ipad
vendor: apple model: ipad air
vendor: apple model: iphone
vendor: apple model: ipod touch
vendor: apple model: macos
Related entries in the VARIoT vulnerabilities database: VAR-202207-1385, VAR-202207-1298

Trust: 5.5

Fetched: Nov. 8, 2022, 9:59 a.m., Published: Sept. 8, 2022, 8:10 a.m.
Vulnerabilities: directory traversal, privilege escalation, format string issue...
Affected productsExternal IDs
vendor: zyxel model: nas542
vendor: zyxel model: nas540
vendor: zyxel model: nas326
vendor: qnap model: photo station
vendor: trend model: security
db: NVD ids: CVE-2022-2030, CVE-2022-34747, CVE-2022-0823, CVE-2022-30526

Trust: 4.0

Fetched: Nov. 8, 2022, 9:58 a.m., Published: Aug. 25, 2022, 2:35 p.m.
Vulnerabilities: command injection
Affected productsExternal IDs
db: NVD ids: CVE-2021-36260
Related entries in the VARIoT vulnerabilities database: VAR-202209-0759, VAR-202208-1294

Trust: 3.75

Fetched: Nov. 8, 2022, 9:57 a.m., Published: Nov. 8, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: webkit
vendor: apple model: macos
db: NVD ids: CVE-2022-32917, CVE-2022-32894

Trust: 3.75

Fetched: Nov. 8, 2022, 9:56 a.m., Published: Nov. 8, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: security

Trust: 4.5

Fetched: Nov. 8, 2022, 9:56 a.m., Published: Aug. 31, 2022, 11:45 a.m.
Vulnerabilities: input validation vulnerability, code execution, os command injection...
Affected productsExternal IDs
vendor: omron model: cx-programmer
vendor: rockwell automation model: kepserver enterprise
vendor: mitsubishi model: melsec iq-r
vendor: mitsubishi model: melsec iq-r series
vendor: rockwell model: kepserver enterprise
vendor: trend micro model: security
vendor: trend model: security
vendor: honeywell model: experion
vendor: mitsubishi electric model: melsec iq-r
vendor: mitsubishi electric model: melsec iq-r series

Trust: 3.5

Fetched: Nov. 8, 2022, 9:55 a.m., Published: Aug. 18, 2022, midnight
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: home
vendor: google model: android
Related entries in the VARIoT vulnerabilities database: VAR-201906-0815, VAR-202210-0198

Trust: 3.75

Fetched: Nov. 8, 2022, 9:55 a.m., Published: Oct. 12, 2022, midnight
Vulnerabilities: information disclosure, authentication bypass
Affected productsExternal IDs
db: NVD ids: CVE-2018-13379, CVE-2022-40684
Related entries in the VARIoT vulnerabilities database: VAR-202211-0468, VAR-202211-1081, VAR-202207-0205

Trust: 5.25

Fetched: Nov. 8, 2022, 9:53 a.m., Published: Nov. 8, 2022, midnight
Vulnerabilities: information disclosure, denial of service, code execution
Affected productsExternal IDs
vendor: samsung model: notes
vendor: samsung model: mobile
vendor: motorola model: android
vendor: motorola model: motorola
vendor: huawei model: huawei
vendor: google model: wifi
vendor: google model: android
vendor: google model: pixel
db: NVD ids: CVE-2022-20447, CVE-2021-1050, CVE-2022-33237, CVE-2022-20454, CVE-2022-38673, CVE-2022-25671, CVE-2021-35122, CVE-2022-20457, CVE-2022-20446, CVE-2022-20462, CVE-2022-20414, CVE-2022-20426, CVE-2022-33236, CVE-2021-35132, CVE-2021-39661, CVE-2022-38676, CVE-2022-20445, CVE-2022-38669, CVE-2022-32601, CVE-2022-20448, CVE-2021-35109, CVE-2022-2209, CVE-2022-32602, CVE-2022-2985, CVE-2022-33239, CVE-2022-20465, CVE-2022-2984, CVE-2022-39105, CVE-2021-35135, CVE-2022-38670, CVE-2022-20463, CVE-2021-35108, CVE-2022-38690, CVE-2022-20441, CVE-2022-33234, CVE-2022-20451, CVE-2022-20453, CVE-2022-20452, CVE-2022-38672, CVE-2022-20450
Related entries in the VARIoT vulnerabilities database: VAR-202208-1345, VAR-202208-1294

Trust: 5.75

Fetched: Nov. 8, 2022, 9:53 a.m., Published: Aug. 18, 2022, 6:21 p.m.
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: webkit
vendor: apple model: macos
vendor: apple model: safari
db: NVD ids: CVE-2022-32893, CVE-2022-32894

Trust: 3.0

Fetched: Nov. 8, 2022, 9:52 a.m., Published: Sept. 27, 2022, 11:22 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: trend model: security

Trust: 3.75

Fetched: Nov. 8, 2022, 9:50 a.m., Published: Oct. 11, 2022, 10:39 p.m.
Vulnerabilities: default password
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202205-1571, VAR-201502-0201, VAR-201803-1769, VAR-202203-1742

Trust: 5.25

Fetched: Nov. 8, 2022, 9:49 a.m., Published: Sept. 5, 2022, 3:53 a.m.
Vulnerabilities: command execution, code execution, arbitrary command execution...
Affected productsExternal IDs
vendor: d-link model: router
vendor: palo model: networks
vendor: palo model: firewall
vendor: palo alto networks model: networks
vendor: palo alto networks model: firewall
db: NVD ids: CVE-2022-28958, CVE-2015-2051, CVE-2018-6530, CVE-2022-26258