VARIoT IoT vulnerabilities database
| VAR-201810-0055 | CVE-2017-18283 | Snapdragon Mobile Input validation vulnerability |
CVSS V2: 6.1 CVSS V3: 6.5 Severity: MEDIUM |
Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 625, SD 835, SD 845, SD 850, SDA660. Snapdragon Mobile Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm QCA9379 and others are products of Qualcomm (Qualcomm). Qualcomm QCA9379 is a WiFi module. SD 210, etc. are central processing unit (CPU) products applied to different platforms. Bluetooth controller is one of the Bluetooth controller components. An attacker could exploit this vulnerability to cause memory corruption. The following products (for mobile devices) are affected: Qualcomm QCA9379; SD 210; SD 212; SD 205; SD 625; SD 835; SD 845; SD 850; SDA660
| VAR-201810-0056 | CVE-2017-18292 | plural Snapdragon Vulnerability related to input validation in products |
CVSS V2: 4.9 CVSS V3: 5.5 Severity: MEDIUM |
Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm MSM8909W, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) for different platforms. An attacker can exploit this vulnerability by calling the Widevine app API continuously to cause the system to restart
| VAR-201810-0063 | CVE-2017-18299 | plural Snapdragon Access control vulnerabilities in products |
CVSS V2: 4.9 CVSS V3: 5.5 Severity: MEDIUM |
Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an access control vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. An input validation vulnerability exists in the Core of several Qualcomm Snapdragon products due to incorrect form merge conversion logic. An attacker could exploit this vulnerability to cause resource exhaustion and QSEE errors
| VAR-201810-0037 | CVE-2017-18300 | Snapdragon Mobile and Snapdragon Wear Vulnerable to information disclosure |
CVSS V2: 4.9 CVSS V3: 5.5 Severity: MEDIUM |
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SDA660. Snapdragon Mobile and Snapdragon Wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. TZ in several Qualcomm Snapdragon products has an information disclosure vulnerability, which is caused by the program not properly clearing the Secure Display buffer. A local attacker could exploit this vulnerability to obtain information. The following products (used in mobile devices and watches) are affected: Qualcomm MDM9206; MDM9607; MDM9650; SD 210; SD 212; SD 205; SD 835; SDA660
| VAR-201810-0391 | CVE-2018-14806 | Advantech WebAccess Path traversal vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. Advantech WebAccess Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Authentication is not required to exploit this vulnerability.The specific flaw exists within the implementation of the 0x2711 IOCTL in the webvrpcs process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment. Advantech WebAccess is prone to the following security vulnerabilities:
1. A stack-based buffer overflow vulnerability
2. A directory-traversal vulnerability
3. An arbitrary-file-deletion vulnerability
4. This may aid in further attacks.
Advantech WebAccess 8.3.1 and prior versions are vulnerable
| VAR-201810-0463 | CVE-2018-17923 | GAIN Electronic Co. Ltd SAGA1-L Series Incorrect authentication vulnerability |
CVSS V2: 6.9 CVSS V3: 6.9 Severity: MEDIUM |
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to reprogram it. SAGA1-L8B There are authentication vulnerabilities in the firmware.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the device programming mechanism. The device is insufficiently protected from unauthorized firmware updates. An attacker can leverage this vulnerability to bypass authentication and install persistent malicious firmware on the device. GAINSAGA1-LSeries is a SAGA1-L series of industrial remote control products from GAINElectronic. A security hole exists in the GAINSAGA1-LSeries product that uses firmware prior to A0.10. GAIN Electronic SAGA1-L Series is prone to the following security vulnerabilities:
1. An local-authentication bypass vulnerability
3
| VAR-201810-0398 | CVE-2018-14820 | Advantech WebAccess Input validation vulnerability |
CVSS V2: 6.4 CVSS V3: 7.5 Severity: HIGH |
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing. Advantech WebAccess Contains an input validation vulnerability.Information may be tampered with. This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of Advantech WebAccess Node. Authentication is not required to exploit this vulnerability.The specific flaw exists within the implementation of the 0x2715 IOCTL in the webvrpcs process. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this functionality to delete files under the context of Administrator. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment. .dll is one of the dynamic link library components. A security vulnerability exists in the .dll component of Advantech WebAccess 8.3.1 and earlier. Advantech WebAccess is prone to the following security vulnerabilities:
1. A stack-based buffer overflow vulnerability
2. A directory-traversal vulnerability
3. An arbitrary-file-deletion vulnerability
4. This may aid in further attacks.
Advantech WebAccess 8.3.1 and prior versions are vulnerable
| VAR-201810-0146 | CVE-2018-18517 | Citrix NetScaler Gateway Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. Citrix NetScaler Gateway Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks
| VAR-201810-1162 | CVE-2018-7911 | plural Huawei Vulnerabilities related to security functions in smartphones |
CVSS V2: 4.9 CVSS V3: 4.6 Severity: MEDIUM |
Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2, BLA-TL00B 8.0.0.113(SP7C01), 8.0.0.118(C01), 8.0.0.120(SP2C01), 8.0.0.125(SP1C01), 8.0.0.125(SP2C01), 8.0.0.125(SP3C01), 8.0.0.126(SP2C01), 8.0.0.126(SP5C01), 8.0.0.127(SP1C01), 8.0.0.128(SP2C01), 8.0.0.129(SP2C01), Charlotte-AL00A 8.1.0.105(SP7C00), 8.1.0.106(SP3C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP3C00), 8.1.0.108(SP6C00), 8.1.0.109(SP2C00), Emily-AL00A 8.1.0.105(SP6C00), 8.1.0.106(SP2C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP2C00), 8.1.0.108(SP6C00), 8.1.0.109(SP5C00) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Gaode Map and can perform some operations to update the Google account. As a result, the FRP function is bypassed. plural Huawei Smartphones have vulnerabilities related to security functions.Information may be tampered with. Huawei ALP-AL00B is a smartphone product of China Huawei. The following products and versions are affected: Huawei ALP-AL00B Version 8.0.0.106(C00), Version 8.0.0.113(SP2C00), Version 8.0.0.113(SP3C00), Version 8.0.0.113(SP7C00), Version 8.0.0.118(C00) , 8.0.0.120 (SP2C00) version, 8.0.0.125 (SP1C00) version, 8.0.0.125 (SP3C00) version, 8.0.0.126 (SP2C00) version, 8.0.0.126 (SP5C00) version, 8.0.0.127 (SP1C00) version, 8.0 .0.128(SP2C00) version; ALP-AL00B-RSC 1.0.0.2 version; BLA-TL00B 8.0.0.113(SP7C01) version, 8.0.0.118(C01) version, 8.0.0.120(SP2C01) version, 8.0.0.125(SP1C01) version Version, 8.0.0.125(SP2C01) version, 8.0.0.125(SP3C01) version, 8.0.0.126(SP2C01) version, 8.0.0.126(SP5C01) version, 8.0.0.127(SP1C01) version, 8.0.0.128(SP2C01) version, 8.0.0.129 (SP2C01) version; Charlotte-AL00A 8.1.0.105 (SP7C00) version, 8.1.0.106 (SP3C00) version, 8.1.0.107 (SP5C00) version, 8.1.0.107 (SP7C00) version, 8.1.0.108 (SP3C00) version , 8.1.0.108 (SP6C00) version, 8.1.0.109 (SP2C00) version; Emily-AL00A 8.1.0.105 (SP6C00) version, 8.1.0.106 (SP2C00) version, 8.1.0.107 (SP5C00) version, 8.1.0.107 (SP7C00) Version, 8.1.0
| VAR-201810-0185 | CVE-2018-18566 | Polycom VVX 500 and 601 Information disclosure vulnerability in devices |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business. Polycom VVX 500 and 601 The device contains an information disclosure vulnerability.Information may be obtained. Polycom VVX is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may aid in further attacks.
Polycom VVX 500/601 version 5.8.0.12848 and prior are vulnerable. Polycom VVX 500 and 601 are IP telephone products of American Polycom (Polycom) company. SIP service is one of the SIP (Session Initiation Protocol) services. The SIP service in Polycom VVX 500 and 601 5.8.0.12848 and earlier versions has a security vulnerability
| VAR-201810-1609 | No CVE | Viprinet VPN Hub Router Cross-Site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
ViprinetVPNHubRouter is a multi-channel VPN router product from ViprinetEurope, Germany. ViprinetVPNHubRouter has a cross-site scripting vulnerability that stems from the lack of input validation and output escaping mechanisms on the CLI interface. By exploiting this vulnerability, an attacker can obtain sensitive information (for example, a private key) or modify the SSL certificate fingerprint of a remote router used in a VPN tunnel.
| VAR-201810-0585 | CVE-2018-15497 | Mitel MiVoice 5330e VoIP Device buffer error vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution. Mitel MiVoice 5330e VoIP The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MitelMiVoice5330eVoIP is an IP phone from Mitel, Canada
| VAR-201810-0401 | CVE-2018-14828 | Advantech WebAccess Improper Rights Management Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level. Advantech WebAccess Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. This vulnerability allows local attackers to escalate privileges on vulnerable installations of Advantech WebAccess Node. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the access control that is set and modified during the installation of the product. The product installation weakens access control restrictions of pre-existing system files and sets weak access control restrictions on new files. Advantech (Advantech) WebAccess software is the core of Advantech's IoT application platform solution, providing users with a user interface based on HTML5 technology to achieve cross-platform and cross-browser data access experience. Advantech WebAccess has an improper rights management vulnerability. Advantech WebAccess is prone to the following security vulnerabilities:
1. A stack-based buffer overflow vulnerability
2. A directory-traversal vulnerability
3. An arbitrary-file-deletion vulnerability
4. This may aid in further attacks.
Advantech WebAccess 8.3.1 and prior versions are vulnerable. Advantech WebAccess is a browser-based HMI/SCADA software developed by Advantech. The software supports dynamic graphic display and real-time data control, and provides functions of remote control and management of automation equipment
| VAR-201810-0425 | CVE-2018-17873 | WiFiRanger Device key management error vulnerability |
CVSS V2: 3.3 CVSS V3: 8.8 Severity: HIGH |
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account. WiFiRanger The device contains a vulnerability related to key management errors.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. WiFiRanger is a WiFi signal repeater
| VAR-201810-0875 | CVE-2018-13115 | KERUI Wifi Endoscope Camera Input validation vulnerability |
CVSS V2: 6.4 CVSS V3: 6.5 Severity: MEDIUM |
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user. KERUI Wifi Endoscope Camera (YPC99) Contains an input validation vulnerability.Information may be obtained and information may be altered. KERUI Wifi Endoscope Camera (YPC99) is a mini endoscope camera
| VAR-201810-0874 | CVE-2018-13114 | KERUI Wifi Endoscope Camera Input validation vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command. KERUI Wifi Endoscope Camera (YPC99) Contains an input validation vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. KERUI Wifi Endoscope Camera (YPC99) is a mini endoscope camera. An attacker can use the 'ssid' value to exploit this vulnerability to execute arbitrary commands
| VAR-201810-0127 | CVE-2018-15703 | Advantech WebAccess Vulnerable to cross-site scripting |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser. Advantech WebAccess Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment
| VAR-201810-0128 | CVE-2018-15704 | Advantech WebAccess Buffer error vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp. Advantech WebAccess Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment
| VAR-201810-0963 | CVE-2018-12673 | SV3C HD Camera Vulnerable to information disclosure |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information. SV3C HD Camera Contains an information disclosure vulnerability.Information may be obtained
| VAR-201810-0962 | CVE-2018-12672 | SV3C L-SERIES HD CAMERA Cross-Site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator. SV3CL-SERIESHDCAMERA is a network camera product of China SV3C Technology Corporation