VARIoT news about IoT security

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 22, 2021, 5:55 p.m.
Vulnerabilities: brute force attack, default credentials
Affected productsExternal IDs

Trust: 3.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 29, 2021, 6:12 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: check point model: check point
Related entries in the VARIoT vulnerabilities database: VAR-202108-1057

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Sept. 14, 2021, 2:43 a.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: apple model: ipad
vendor: apple model: ipod touch
vendor: apple model: watchos
vendor: apple model: ipad air
vendor: apple model: macos
vendor: apple model: iphone
db: NVD ids: CVE-2021-30860

Trust: 4.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Sept. 22, 2021, 11:54 a.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: cisco model: access points
vendor: cisco model: catalyst
vendor: cisco model: wireless controller
vendor: cisco model: wireless lan controller
vendor: cisco model: catalyst 9800

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 24, 2021, 9:48 p.m.
Vulnerabilities: cross-site scripting
Affected productsExternal IDs

Trust: 4.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 26, 2021, 1:13 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs

Trust: 3.5

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Jan. 3, 2022, midnight
Vulnerabilities: code execution
Affected productsExternal IDs
vendor: apple model: watch
vendor: apple model: watchos
vendor: apple model: macos
vendor: apple model: iphone
Related entries in the VARIoT vulnerabilities database: VAR-202005-0685, VAR-202110-1796, VAR-202005-0696, VAR-202007-1057

Trust: 5.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 23, 2021, 6:15 p.m.
Vulnerabilities: denial of service, buffer overflow
Affected productsExternal IDs
vendor: cisco model: firepower
vendor: cisco model: device manager
vendor: cisco model: cisco adaptive security appliance
vendor: cisco model: adaptive security appliance
vendor: cisco model: firepower threat defense
db: NVD ids: CVE-2020-3187, CVE-2021-34704, CVE-2020-3259, CVE-2020-3452

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 24, 2021, 1:16 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: check point model: check point
vendor: vivo model: vivo
vendor: xiaomi model: browser
db: NVD ids: CVE-2021-0673, CVE-2021-0663, CVE-2021-0661, CVE-2021-0662

Trust: 3.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Dec. 10, 2021, midnight
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2020-17087

Trust: 3.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 25, 2021, 2:02 p.m.
Vulnerabilities: sql injection
Affected productsExternal IDs
Related entries in the VARIoT vulnerabilities database: VAR-202111-0697

Trust: 4.25

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 23, 2021, 9:47 p.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2021-41379

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 24, 2021, 11:25 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: xiaomi model: redmi
vendor: check point model: check point
db: NVD ids: CVE-2021-0663, CVE-2021-0673, CVE-2021-0661, CVE-2021-0662
Related entries in the VARIoT vulnerabilities database: VAR-201906-0815, VAR-202008-0193, VAR-202007-0079

Trust: 4.5

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 23, 2021, 6:27 a.m.
Vulnerabilities: privilege escalation, code execution, authentication vulnerability...
Affected productsExternal IDs
vendor: filezilla model: server
vendor: filezilla model: filezilla
db: NVD ids: CVE-2018-13379, CVE-2019-5591, CVE-2021-34473, CVE-2020-12812
Related entries in the VARIoT vulnerabilities database: VAR-202106-0639, VAR-202107-1010

Trust: 3.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 3, 2021, 1:48 a.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2021-1675, CVE-2021-34527

Trust: 4.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Nov. 3, 2021, 6:39 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: android
db: NVD ids: CVE-2021-1048
Related entries in the VARIoT vulnerabilities database: VAR-202111-1435

Trust: 5.75

Fetched: Nov. 29, 2021, 2:59 p.m., Published: Jan. 5, 2022, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
vendor: huawei model: cloudengine 7800
vendor: huawei model: huawei
vendor: huawei model: cloudengine 5800
vendor: huawei model: cloudengine 12800
vendor: huawei model: cloudengine 6800
vendor: huawei model: cloudengine
db: NVD ids: CVE-2021-39976
Related entries in the VARIoT vulnerabilities database: VAR-202111-0656

Trust: 5.25

Fetched: Nov. 29, 2021, 2:59 p.m., Published: -
Vulnerabilities: cross-site request forgery, integer overflow, code execution...
Affected productsExternal IDs
vendor: quagga model: quagga
vendor: realtek model: rtl8195am
vendor: node.js model: node.js
db: NVD ids: CVE-2021-44219, CVE-2021-43776, CVE-2021-36799, CVE-2021-44140, CVE-2021-43574, CVE-2021-43578, CVE-2021-44094, CVE-2021-43576, CVE-2021-43616, CVE-2021-43996, CVE-2021-44026, CVE-2021-43975, CVE-2021-43669, CVE-2021-44143, CVE-2021-44025, CVE-2021-43620, CVE-2021-43778, CVE-2021-43668, CVE-2021-44036, CVE-2021-44033, CVE-2021-43777, CVE-2021-44150, CVE-2021-43611, CVE-2021-43780, CVE-2021-43617, CVE-2021-43618, CVE-2021-44147, CVE-2021-43571, CVE-2021-44093, CVE-2021-43569, CVE-2021-43997, CVE-2021-43577, CVE-2021-44225, CVE-2021-44144, CVE-2021-43979, CVE-2009-1234, CVE-2021-43667, CVE-2021-43775, CVE-2021-43582, CVE-2021-44038, CVE-2021-44079, CVE-2021-43572, CVE-2021-43573, CVE-2021-43976, CVE-2021-43610, CVE-2021-43575, CVE-2021-43581, CVE-2021-44037, CVE-2021-43977, CVE-2021-43785, CVE-2021-43570, CVE-2021-44223, CVE-2021-33056

Trust: 3.5

Fetched: Nov. 29, 2021, 2:59 p.m., Published: -
Vulnerabilities: cross-site scripting, sql injection, command injection
Affected productsExternal IDs
vendor: totolink model: a3002ru
vendor: netgear model: r9000
vendor: drobo model: drobo 5n2
vendor: buffalo model: ts5600d1206

Trust: 3.0

Fetched: Nov. 29, 2021, 2:59 p.m., Published: -
Vulnerabilities: denial of service
Affected productsExternal IDs