VARIoT news about IoT security

Trust: 3.5

Fetched: June 20, 2025, 10:17 a.m., Published: Feb. 10, 2023, 3:07 a.m.
Vulnerabilities: header injection, sql injection, code execution
Affected productsExternal IDs

Trust: 4.5

Fetched: June 20, 2025, 10:17 a.m., Published: June 18, 2025, midnight
Vulnerabilities: code execution
Affected productsExternal IDs

Trust: 3.25

Fetched: June 20, 2025, 10:16 a.m., Published: May 22, 2025, 11:15 p.m.
Vulnerabilities: -
Affected productsExternal IDs
db: NVD ids: CVE-2025-4338
Related entries in the VARIoT vulnerabilities database: VAR-202304-2073

Trust: 3.75

Fetched: June 20, 2025, 10:09 a.m., Published: June 17, 2025, midnight
Vulnerabilities: command injection, os command injection
Affected productsExternal IDs
db: NVD ids: CVE-2023-28771, CVE-2024-40891
Related entries in the VARIoT vulnerabilities database: VAR-202112-0566

Trust: 3.75

Fetched: June 20, 2025, 10:08 a.m., Published: June 4, 2025, 4:38 p.m.
Vulnerabilities: -
Affected productsExternal IDs
vendor: node.js model: node.js
db: NVD ids: CVE-2021-44228

Trust: 3.25

Fetched: June 20, 2025, 10:06 a.m., Published: June 20, 2025, 4:40 a.m.
Vulnerabilities: memory leak, buffer overflow, code execution...
Affected productsExternal IDs

Trust: 6.0

Fetched: June 20, 2025, 10:06 a.m., Published: June 18, 2025, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: meraki mx
vendor: cisco model: series
db: NVD ids: CVE-2025-20271

Trust: 6.0

Fetched: June 20, 2025, 10:06 a.m., Published: -
Vulnerabilities: buffer overflow, denial of service
Affected productsExternal IDs
vendor: clamav model: clamav
db: NVD ids: CVE-2025-20260

Trust: 4.75

Fetched: June 20, 2025, 10:05 a.m., Published: June 18, 2025, 3:56 p.m.
Vulnerabilities: information disclosure
Affected productsExternal IDs
vendor: cisco model: clamav
vendor: clamav model: clamav
Related entries in the VARIoT vulnerabilities database: VAR-202102-1379, VAR-202301-0962, VAR-202012-0105, VAR-202112-0566

Trust: 4.5

Fetched: June 20, 2025, 10:04 a.m., Published: June 19, 2025, 9:12 p.m.
Vulnerabilities: privilege escalation, improper access control, information disclosure
Affected productsExternal IDs
vendor: dram model: dram
db: NVD ids: CVE-2021-27148, CVE-2023-20025, CVE-2020-12522, CVE-2021-44228, CVE-2021-29457, CVE-2022-30552, CVE-2019-12586, CVE-2022-26321

Trust: 5.25

Fetched: June 20, 2025, 10:04 a.m., Published: June 18, 2025, 9:54 a.m.
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2025-6019, CVE-2025-6018

Trust: 4.75

Fetched: June 20, 2025, 10:03 a.m., Published: June 17, 2025, 8:25 p.m.
Vulnerabilities: privilege escalation, code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-6019, CVE-2025-6018

Trust: 4.75

Fetched: June 20, 2025, 10:02 a.m., Published: June 19, 2025, midnight
Vulnerabilities: denial of service
Affected productsExternal IDs
db: NVD ids: CVE-2024-44074, CVE-2024-21864

Trust: 4.25

Fetched: June 20, 2025, 10:01 a.m., Published: June 20, 2025, 12:08 a.m.
Vulnerabilities: code execution
Affected productsExternal IDs
db: NVD ids: CVE-2025-5310

Trust: 4.75

Fetched: June 20, 2025, 9:55 a.m., Published: June 19, 2025, 7:44 a.m.
Vulnerabilities: service crash
Affected productsExternal IDs
vendor: cisco model: meraki mx
vendor: cisco model: anyconnect vpn client
vendor: cisco model: sd-wan
vendor: cisco model: vpn client
vendor: cisco model: series
vendor: cisco model: meraki mx firmware
db: NVD ids: CVE-2025-20271

Trust: 5.75

Fetched: June 20, 2025, 9:55 a.m., Published: June 19, 2025, 1:48 a.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: meraki mx
vendor: cisco model: anyconnect vpn client
vendor: cisco model: sd-wan
vendor: cisco model: vpn client
vendor: cisco model: series
db: NVD ids: CVE-2025-20271

Trust: 4.0

Fetched: June 20, 2025, 9:55 a.m., Published: June 18, 2025, midnight
Vulnerabilities: privilege escalation
Affected productsExternal IDs
db: NVD ids: CVE-2025-6019, CVE-2025-6018

Trust: 5.0

Fetched: June 20, 2025, 9:54 a.m., Published: June 19, 2025, 7:30 p.m.
Vulnerabilities: denial of service
Affected productsExternal IDs
vendor: cisco model: series
vendor: cisco model: meraki mx
db: NVD ids: CVE-2025-20271

Trust: 5.5

Fetched: June 20, 2025, 9:48 a.m., Published: June 19, 2025, 5:41 a.m.
Vulnerabilities: cross-site scripting, default credentials, privilege escalation...
Affected productsExternal IDs
vendor: siemens model: simatic s7-1500
vendor: siemens model: ruggedcom
vendor: siemens model: simatic
vendor: palo alto networks model: firewall
vendor: palo alto networks model: networks
vendor: palo model: firewall
vendor: palo model: networks
db: NVD ids: CVE-2025-40585

Trust: 3.25

Fetched: June 20, 2025, 9:35 a.m., Published: -
Vulnerabilities: -
Affected productsExternal IDs
vendor: google model: home