VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201710-0984 CVE-2017-14971 Infocus Mondopad Information Disclosure Vulnerability CVSS V2: 4.3
CVSS V3: 5.5
Severity: MEDIUM
Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scenario, the attacker provides an Excel spreadsheet, and the attacker-controller server receives the victim's NetNTLMv2 hash. InFocusMondopad is a full-featured touch-screen whiteboard from InFocus
VAR-201710-0985 CVE-2017-14972 InFocus Mondopad Vulnerabilities in authentication CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file. InFocus Mondopad Contains an authentication vulnerability.Information may be obtained. InFocusMondopad is a full-featured touch-screen whiteboard from InFocus. An authentication bypass vulnerability exists in the InFocusMondopad version 2.2.08. A remote attacker can exploit this vulnerability to obtain information
VAR-201710-1051 CVE-2017-15073 Intel Puma Denial of Service Vulnerability (CNVD-2017-30927) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1050 CVE-2017-15072 Intel Puma Denial of Service Vulnerability (CNVD-2017-30928) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1049 CVE-2017-15071 Intel Puma Denial of Service Vulnerability (CNVD-2017-30929) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1048 CVE-2017-15070 Intel Puma Denial of Service Vulnerability (CNVD-2017-30930) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1025 CVE-2017-15069 Intel Puma Denial of Service Vulnerability (CNVD-2017-30931) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1024 CVE-2017-15068 Intel Puma Denial of Service Vulnerability (CNVD-2017-30932) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1023 CVE-2017-15067 Intel Puma Denial of Service Vulnerability (CNVD-2017-30933) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1022 CVE-2017-15066 Intel Puma Denial of Service Vulnerability (CNVD-2017-30935) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1021 CVE-2017-15065 Intel Puma Denial of Service Vulnerability (CNVD-2017-30934) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-1020 CVE-2017-15064 Intel Puma Denial of Service Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue associated with the originally named downstream provider. Notes: none. IntelPuma is a system-on-chip (SoC) from Intel. Intel Puma has a denial of service vulnerability that allows remote attackers to cause denial of service (degraded performance) by sending the right amount of small packets to many TCP or UDP ports
VAR-201710-0954 CVE-2017-5700 plural Intel NUC Kit Vulnerabilities related to certificate and password management in product firmware CVSS V2: 7.2
CVSS V3: 8.4
Severity: HIGH
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage. Intel NUC7i3BNK , NUC7i3BNH , NUC7i5BNK , NUC7i5BNH ,and NUC7i7BNH Vulnerabilities related to certificate and password management exist in the firmware.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. IntelBootgaurd has a local security bypass vulnerability that can be exploited by local attackers to bypass certain security restrictions. IntelNUC7i3BNK and other products are CPU (Central Processing Unit) products of Intel Corporation of the United States. A privilege elevation vulnerability exists in system firmware in several Intel products due to insufficient verification input by the program. An attacker could exploit the vulnerability to exploit arbitrary code by manipulating memory. Intel NUC is a powerful 4x4 inch micro PC with entertainment, gaming and work features, a customizable motherboard that supports all the memory, storage and operating systems you need. Multiple Intel products are prone to a local information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. Intel NUC7i3BNK, etc. The following products and versions are affected: NUC7i3BNK BN0049 and earlier; NUC7i3BNH BN0049 and earlier; NUC7i5BNK BN0049 and earlier; NUC7i5BNH BN0049 and earlier; NUC7i7BNH BN0049 and earlier
VAR-201710-0957 CVE-2017-5701 plural Intel NUC Kit Vulnerabilities related to authorization, authority, and access control in product firmware CVSS V2: 4.4
CVSS V3: 7.1
Severity: HIGH
Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS Recovery. Intel NUC7i3BNK , NUC7i3BNH , NUC7i5BNK , NUC7i5BNH ,and NUC7i7BNH Vulnerabilities related to authorization, permissions and access control exist in the firmware.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. IntelNUC7i3BNK and other products are CPU (Central Processing Unit) products of Intel Corporation of the United States. IntelSPIWriteProtection has a local security bypass vulnerability that can be exploited by local attackers to bypass certain security restrictions. Intel Bootgaurd is prone to a local security-bypass vulnerability. Other attacks are also possible. Intel NUC7i3BNK, etc. An attacker could exploit this vulnerability to execute arbitrary code. The following products and versions are affected: NUC7i3BNK BN0049 and earlier; NUC7i3BNH BN0049 and earlier; NUC7i5BNK BN0049 and earlier; NUC7i5BNH BN0049 and earlier; NUC7i7BNH BN0049 and earlier
VAR-201710-1304 CVE-2017-8017 EMC Network Configuration Manager Cross-Site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
EMC Network Configuration Manager (NCM) 9.3.x, 9.4.0.x, 9.4.1.x, and 9.4.2.x is affected by a reflected cross-site scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system. that enables model-based automated network compliance, change, and configuration management to quickly perform network change and configuration management tasks. A cross-site scripting vulnerability exists in EMCNCM. This vulnerability could be exploited by a remote attacker to control the affected system. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. Link to remedies: https://support.emc.com/products/31946_Service-Assurance-Suite Credit: EMC would like to thank Lukasz Plonka for reporting this issue. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJZ1mSSAAoJEHbcu+fsE81Zul4H/0rz/w9V+zWyjUowYuYgKWOd c03fYbO6BEdJ/HZ05eblXDnNtp3HC6B+Z0PH8PlapfIxvGLezRvb2oidyy/BoNdc TMlVsSb9hJWEMykRMWsyT94C/wqzp3Cjm5qi8jFSdzMjfCqbaaAWCpgyg6F1VMCy vc6SAGHL9qfBqzQ1f2WR6sZMsG16qu9VgsmLciYPCGhfmqBMiWgdhcOf3cS+aDOO 6FX2ZrDuumxfFaWoS9+pG5Nz65RHTVljn6t3Xo+NhfQDS/bVbWjv8m/Jd8M0dwuL cAZsM2ukWP8DVDX0xFd0CTioPS9s2DyvThacPF1rCn7Q5qC0OgV6cAqcNgRPfsM= =QUiL -----END PGP SIGNATURE-----
VAR-201710-1117 CVE-2017-12732 GE CIMPLICITY Buffer error vulnerability CVSS V2: 4.9
CVSS V3: 6.8
Severity: MEDIUM
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary remote code execution. GE CIMPLICITY Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. GE CIMPLICITY is an HMI software. GE CIMPLICITY has a stack buffer overflow vulnerability that allows remote attackers to exploit a vulnerability to submit a special request to crash an application or execute arbitrary code. Failed exploit attempts will likely result in denial-of-service conditions
VAR-201712-1117 CVE-2017-9944 Siemens 7KT PAC1200 Data Manager Authentication Bypass Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network. Siemens 7KT PAC1200 data manager (7KT1260) Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. 7KTPAC1200datamanager (7KT1260) fromtheSENTRONportfolio is a fully integrated smart meter with a web interface. This may aid in further attacks
VAR-201710-0647 CVE-2017-12269 Cisco Spark Vulnerable to cross-site scripting CVSS V2: 3.5
CVSS V3: 5.4
Severity: MEDIUM
A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected software. An attacker could exploit this vulnerability by injecting XSS content into the web UI of the affected software. A successful exploit could allow the attacker to force a user to execute code of the attacker's choosing or allow the attacker to retrieve sensitive information from the user. Cisco Bug IDs: CSCvf70587, CSCvf70592. Vendors have confirmed this vulnerability Bug ID CSCvf70587 , CSCvf70592 It is released as.Information may be obtained and information may be altered. Other attacks are also possible. By providing a virtual space, the solution allows teams at any location to work together, call and video, discuss issues, store team files and documents, etc
VAR-201710-1028 CVE-2017-15008 PRTG Network Monitor Vulnerable to cross-site scripting CVSS V2: 3.5
CVSS V3: 4.8
Severity: MEDIUM
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all sensor titles, related to incorrect error handling for a %00 in the SRC attribute of an IMG element. PRTG Network Monitor Contains a cross-site scripting vulnerability.Information may be obtained and information may be altered
VAR-201710-0630 CVE-2017-12244 Cisco Firepower System Software input validation vulnerability CVSS V2: 5.0
CVSS V3: 8.6
Severity: HIGH
A vulnerability in the detection engine parsing of IPv6 packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause high CPU utilization or to cause a denial of service (DoS) condition because the Snort process restarts unexpectedly. The vulnerability is due to improper input validation of the fields in the IPv6 extension header packet. An attacker could exploit this vulnerability by sending a malicious IPv6 packet to the detection engine on the targeted device. An exploit could allow the attacker to cause a DoS condition if the Snort process restarts and traffic inspection is bypassed or traffic is dropped. This vulnerability is specific to IPv6 traffic only. This vulnerability affects Cisco Firepower System Software Releases 6.0 and later when the software has one or more file action policies configured and is running on any of the following Cisco products: 3000 Series Industrial Security Appliances (ISR), Adaptive Security Appliance (ASA) 5500-X Series with FirePOWER Services, Adaptive Security Appliance (ASA) 5500-X Series Next-Generation Firewalls, Advanced Malware Protection (AMP) for Networks, 7000 Series Appliances, Advanced Malware Protection (AMP) for Networks, 8000 Series Appliances, FirePOWER 7000 Series Appliances, FirePOWER 8000 Series Appliances, Firepower Threat Defense for Integrated Services Routers (ISRs), Firepower 2100 Series Security Appliances, Firepower 4100 Series Security Appliances, Firepower 9300 Series Security Appliances, Virtual Next-Generation Intrusion Prevention System (NGIPSv) for VMware. Cisco Bug IDs: CSCvd34776. Cisco Firepower System The software contains input validation vulnerabilities and resource management vulnerabilities. Vendors have confirmed this vulnerability Bug ID CSCvd34776 It is released as.Service operation interruption (DoS) There is a possibility of being put into a state. FirepowerSystemSoftware is a set of firewall software used in it