VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201810-0055 CVE-2017-18283 Snapdragon Mobile Input validation vulnerability CVSS V2: 6.1
CVSS V3: 6.5
Severity: MEDIUM
Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QCA9379, SD 210/SD 212/SD 205, SD 625, SD 835, SD 845, SD 850, SDA660. Snapdragon Mobile Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm QCA9379 and others are products of Qualcomm (Qualcomm). Qualcomm QCA9379 is a WiFi module. SD 210, etc. are central processing unit (CPU) products applied to different platforms. Bluetooth controller is one of the Bluetooth controller components. An attacker could exploit this vulnerability to cause memory corruption. The following products (for mobile devices) are affected: Qualcomm QCA9379; SD 210; SD 212; SD 205; SD 625; SD 835; SD 845; SD 850; SDA660
VAR-201810-0056 CVE-2017-18292 plural Snapdragon Vulnerability related to input validation in products CVSS V2: 4.9
CVSS V3: 5.5
Severity: MEDIUM
Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm MSM8909W, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) for different platforms. An attacker can exploit this vulnerability by calling the Widevine app API continuously to cause the system to restart
VAR-201810-0063 CVE-2017-18299 plural Snapdragon Access control vulnerabilities in products CVSS V2: 4.9
CVSS V3: 5.5
Severity: MEDIUM
Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains an access control vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. An input validation vulnerability exists in the Core of several Qualcomm Snapdragon products due to incorrect form merge conversion logic. An attacker could exploit this vulnerability to cause resource exhaustion and QSEE errors
VAR-201810-0037 CVE-2017-18300 Snapdragon Mobile and Snapdragon Wear Vulnerable to information disclosure CVSS V2: 4.9
CVSS V3: 5.5
Severity: MEDIUM
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SDA660. Snapdragon Mobile and Snapdragon Wear Contains an information disclosure vulnerability.Information may be obtained. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. TZ in several Qualcomm Snapdragon products has an information disclosure vulnerability, which is caused by the program not properly clearing the Secure Display buffer. A local attacker could exploit this vulnerability to obtain information. The following products (used in mobile devices and watches) are affected: Qualcomm MDM9206; MDM9607; MDM9650; SD 210; SD 212; SD 205; SD 835; SDA660
VAR-201810-0391 CVE-2018-14806 Advantech WebAccess Path traversal vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code. Advantech WebAccess Contains a path traversal vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Authentication is not required to exploit this vulnerability.The specific flaw exists within the implementation of the 0x2711 IOCTL in the webvrpcs process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment. Advantech WebAccess is prone to the following security vulnerabilities: 1. A stack-based buffer overflow vulnerability 2. A directory-traversal vulnerability 3. An arbitrary-file-deletion vulnerability 4. This may aid in further attacks. Advantech WebAccess 8.3.1 and prior versions are vulnerable
VAR-201810-0463 CVE-2018-17923 GAIN Electronic Co. Ltd SAGA1-L Series Incorrect authentication vulnerability CVSS V2: 6.9
CVSS V3: 6.9
Severity: MEDIUM
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to an attack that an attacker with physical access to the product may able to reprogram it. SAGA1-L8B There are authentication vulnerabilities in the firmware.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the device programming mechanism. The device is insufficiently protected from unauthorized firmware updates. An attacker can leverage this vulnerability to bypass authentication and install persistent malicious firmware on the device. GAINSAGA1-LSeries is a SAGA1-L series of industrial remote control products from GAINElectronic. A security hole exists in the GAINSAGA1-LSeries product that uses firmware prior to A0.10. GAIN Electronic SAGA1-L Series is prone to the following security vulnerabilities: 1. An local-authentication bypass vulnerability 3
VAR-201810-0398 CVE-2018-14820 Advantech WebAccess Input validation vulnerability CVSS V2: 6.4
CVSS V3: 7.5
Severity: HIGH
Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing. Advantech WebAccess Contains an input validation vulnerability.Information may be tampered with. This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of Advantech WebAccess Node. Authentication is not required to exploit this vulnerability.The specific flaw exists within the implementation of the 0x2715 IOCTL in the webvrpcs process. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this functionality to delete files under the context of Administrator. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment. .dll is one of the dynamic link library components. A security vulnerability exists in the .dll component of Advantech WebAccess 8.3.1 and earlier. Advantech WebAccess is prone to the following security vulnerabilities: 1. A stack-based buffer overflow vulnerability 2. A directory-traversal vulnerability 3. An arbitrary-file-deletion vulnerability 4. This may aid in further attacks. Advantech WebAccess 8.3.1 and prior versions are vulnerable
VAR-201810-0146 CVE-2018-18517 Citrix NetScaler Gateway Vulnerable to cross-site scripting CVSS V2: 3.5
CVSS V3: 4.8
Severity: MEDIUM
Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. Citrix NetScaler Gateway Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks
VAR-201810-1162 CVE-2018-7911 plural Huawei Vulnerabilities related to security functions in smartphones CVSS V2: 4.9
CVSS V3: 4.6
Severity: MEDIUM
Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2, BLA-TL00B 8.0.0.113(SP7C01), 8.0.0.118(C01), 8.0.0.120(SP2C01), 8.0.0.125(SP1C01), 8.0.0.125(SP2C01), 8.0.0.125(SP3C01), 8.0.0.126(SP2C01), 8.0.0.126(SP5C01), 8.0.0.127(SP1C01), 8.0.0.128(SP2C01), 8.0.0.129(SP2C01), Charlotte-AL00A 8.1.0.105(SP7C00), 8.1.0.106(SP3C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP3C00), 8.1.0.108(SP6C00), 8.1.0.109(SP2C00), Emily-AL00A 8.1.0.105(SP6C00), 8.1.0.106(SP2C00), 8.1.0.107(SP5C00), 8.1.0.107(SP7C00), 8.1.0.108(SP2C00), 8.1.0.108(SP6C00), 8.1.0.109(SP5C00) have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can login the configuration flow by Gaode Map and can perform some operations to update the Google account. As a result, the FRP function is bypassed. plural Huawei Smartphones have vulnerabilities related to security functions.Information may be tampered with. Huawei ALP-AL00B is a smartphone product of China Huawei. The following products and versions are affected: Huawei ALP-AL00B Version 8.0.0.106(C00), Version 8.0.0.113(SP2C00), Version 8.0.0.113(SP3C00), Version 8.0.0.113(SP7C00), Version 8.0.0.118(C00) , 8.0.0.120 (SP2C00) version, 8.0.0.125 (SP1C00) version, 8.0.0.125 (SP3C00) version, 8.0.0.126 (SP2C00) version, 8.0.0.126 (SP5C00) version, 8.0.0.127 (SP1C00) version, 8.0 .0.128(SP2C00) version; ALP-AL00B-RSC 1.0.0.2 version; BLA-TL00B 8.0.0.113(SP7C01) version, 8.0.0.118(C01) version, 8.0.0.120(SP2C01) version, 8.0.0.125(SP1C01) version Version, 8.0.0.125(SP2C01) version, 8.0.0.125(SP3C01) version, 8.0.0.126(SP2C01) version, 8.0.0.126(SP5C01) version, 8.0.0.127(SP1C01) version, 8.0.0.128(SP2C01) version, 8.0.0.129 (SP2C01) version; Charlotte-AL00A 8.1.0.105 (SP7C00) version, 8.1.0.106 (SP3C00) version, 8.1.0.107 (SP5C00) version, 8.1.0.107 (SP7C00) version, 8.1.0.108 (SP3C00) version , 8.1.0.108 (SP6C00) version, 8.1.0.109 (SP2C00) version; Emily-AL00A 8.1.0.105 (SP6C00) version, 8.1.0.106 (SP2C00) version, 8.1.0.107 (SP5C00) version, 8.1.0.107 (SP7C00) Version, 8.1.0
VAR-201810-0185 CVE-2018-18566 Polycom VVX 500 and 601 Information disclosure vulnerability in devices CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business. Polycom VVX 500 and 601 The device contains an information disclosure vulnerability.Information may be obtained. Polycom VVX is prone to an information-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may aid in further attacks. Polycom VVX 500/601 version 5.8.0.12848 and prior are vulnerable. Polycom VVX 500 and 601 are IP telephone products of American Polycom (Polycom) company. SIP service is one of the SIP (Session Initiation Protocol) services. The SIP service in Polycom VVX 500 and 601 5.8.0.12848 and earlier versions has a security vulnerability
VAR-201810-1609 No CVE Viprinet VPN Hub Router Cross-Site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
ViprinetVPNHubRouter is a multi-channel VPN router product from ViprinetEurope, Germany. ViprinetVPNHubRouter has a cross-site scripting vulnerability that stems from the lack of input validation and output escaping mechanisms on the CLI interface. By exploiting this vulnerability, an attacker can obtain sensitive information (for example, a private key) or modify the SSL certificate fingerprint of a remote router used in a VPN tunnel.
VAR-201810-0585 CVE-2018-15497 Mitel MiVoice 5330e VoIP Device buffer error vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution. Mitel MiVoice 5330e VoIP The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MitelMiVoice5330eVoIP is an IP phone from Mitel, Canada
VAR-201810-0401 CVE-2018-14828 Advantech WebAccess Improper Rights Management Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level. Advantech WebAccess Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. This vulnerability allows local attackers to escalate privileges on vulnerable installations of Advantech WebAccess Node. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the access control that is set and modified during the installation of the product. The product installation weakens access control restrictions of pre-existing system files and sets weak access control restrictions on new files. Advantech (Advantech) WebAccess software is the core of Advantech's IoT application platform solution, providing users with a user interface based on HTML5 technology to achieve cross-platform and cross-browser data access experience. Advantech WebAccess has an improper rights management vulnerability. Advantech WebAccess is prone to the following security vulnerabilities: 1. A stack-based buffer overflow vulnerability 2. A directory-traversal vulnerability 3. An arbitrary-file-deletion vulnerability 4. This may aid in further attacks. Advantech WebAccess 8.3.1 and prior versions are vulnerable. Advantech WebAccess is a browser-based HMI/SCADA software developed by Advantech. The software supports dynamic graphic display and real-time data control, and provides functions of remote control and management of automation equipment
VAR-201810-0425 CVE-2018-17873 WiFiRanger Device key management error vulnerability CVSS V2: 3.3
CVSS V3: 8.8
Severity: HIGH
An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account. WiFiRanger The device contains a vulnerability related to key management errors.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. WiFiRanger is a WiFi signal repeater
VAR-201810-0875 CVE-2018-13115 KERUI Wifi Endoscope Camera Input validation vulnerability CVSS V2: 6.4
CVSS V3: 6.5
Severity: MEDIUM
Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user. KERUI Wifi Endoscope Camera (YPC99) Contains an input validation vulnerability.Information may be obtained and information may be altered. KERUI Wifi Endoscope Camera (YPC99) is a mini endoscope camera
VAR-201810-0874 CVE-2018-13114 KERUI Wifi Endoscope Camera Input validation vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command. KERUI Wifi Endoscope Camera (YPC99) Contains an input validation vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. KERUI Wifi Endoscope Camera (YPC99) is a mini endoscope camera. An attacker can use the 'ssid' value to exploit this vulnerability to execute arbitrary commands
VAR-201810-0127 CVE-2018-15703 Advantech WebAccess Vulnerable to cross-site scripting CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser. Advantech WebAccess Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment
VAR-201810-0128 CVE-2018-15704 Advantech WebAccess Buffer error vulnerability CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp. Advantech WebAccess Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Advantech WebAccess is a suite of browser-based HMI/SCADA software from Advantech. The software supports dynamic graphical display and real-time data control, and provides the ability to remotely control and manage automation equipment
VAR-201810-0963 CVE-2018-12673 SV3C HD Camera Vulnerable to information disclosure CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information. SV3C HD Camera Contains an information disclosure vulnerability.Information may be obtained
VAR-201810-0962 CVE-2018-12672 SV3C L-SERIES HD CAMERA Cross-Site Scripting Vulnerability CVSS V2: 3.5
CVSS V3: 5.4
Severity: MEDIUM
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator. SV3CL-SERIESHDCAMERA is a network camera product of China SV3C Technology Corporation