VARIoT IoT vulnerabilities database
| VAR-201707-0535 | CVE-2017-11420 | plural ASUS For devices Asuswrt-Merlin Firmware and ASUS Firmware network map ASUS_Discovery.c Vulnerable to stack-based buffer overflow |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Stack-based buffer overflow in ASUS_Discovery.c in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code via long device information that is mishandled during a strcat to a device list. ASUSRT-AC5300 is the RT series router product of ASUS. Asuswrt-Merlin is the firmware running in it. The following products are affected: ASUS RT-AC5300; RT_AC1900P; RT-AC68U; RT-AC68P; RT-AC88U; AC51U; RT-N18U; RT-N66U; RT-N56U; RT-AC3200; RT-AC3100; RT_AC1200GU; RT_AC1200G; RT_N12+_PRO; RT-N16; RT-N300
| VAR-201711-0698 | CVE-2017-11402 | Belden Hirschmann Tofino Xenon Security Appliance Vulnerabilities related to security functions |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OPC classic and in custom netfilter modules allow an attacker to remotely activate rules on the firewall and to connect to any TCP port of a protected asset, thus bypassing the firewall. The attack methodology is a crafted OPC dynamic port shift. Belden Hirschmann Tofino Xenon Security Appliance Contains vulnerabilities related to security features.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Both OPC classic and custom netfilter moudles are functional modules. OPC classic is a process control module. custom netfilter is a custom network filtering module. An attacker could exploit this vulnerability to bypass firewalls
| VAR-201711-0696 | CVE-2017-11400 | Belden Hirschmann Tofino Xenon Security Appliance Permissions vulnerability |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: MEDIUM |
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlled, data. This occurs because the appliance_config file is signed but the .tar.sec file is unsigned. Belden Hirschmann Tofino Xenon Security Appliance Contains a permission vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state
| VAR-201711-0697 | CVE-2017-11401 | Belden Hirschmann Tofino Xenon Security Appliance Data processing vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering. Belden Hirschmann Tofino Xenon Security Appliance Contains a data processing vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. ModBus DPI filter is one of the filters. The vulnerability stems from the fact that the program does not correctly process the mbap.length field of ModBus packets
| VAR-201709-0736 | CVE-2017-11350 | Axesstel MU553S Cross-Site Request Forgery Vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices. Axesstel MU553S The device contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. AxesstelMU553S is a router from Axesstel, USA. A remote attacker could exploit this vulnerability to perform unauthorized operations. Axesstel MU553S is a router of Axesstel Company in the United States
| VAR-201707-0956 | CVE-2017-6753 | plural Cisco WebEx Product buffer error vulnerability |
CVSS V2: 9.3 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037. plural Cisco WebEx The product contains a buffer error vulnerability. Vendors have confirmed this vulnerability Bug ID CSCvf15012 , CSCvf15020 , CSCvf15030 , CSCvf15033 , CSCvf15036 ,and CSCvf15037 It is released as.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Google Chrome for Windows is a Windows-based web browser developed by Google (Google). Mozilla Firefox for Windows is an open source web browser based on the Windows platform from the Mozilla Foundation of the United States
| VAR-201710-0916 | CVE-2017-11322 |
UCOPIA Wireless Appliance Vulnerabilities related to authorization, permissions, and access control
Related entries in the VARIoT exploits database: VAR-E-201709-0048 |
CVSS V2: 7.2 CVSS V3: 8.2 Severity: HIGH |
The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client. UCOPIA Wireless Appliance Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. UCOPIAWirelessAppliance is a wireless device from UCOPIA, France. A security vulnerability exists in the chroothole_client executable file in versions prior to UCOPIAWirelessAppliance 5.1.8
| VAR-201710-0915 | CVE-2017-11321 |
UCOPIA Wireless Appliance Vulnerabilities related to authorization, permissions, and access control
Related entries in the VARIoT exploits database: VAR-E-201709-0008 |
CVSS V2: 6.5 CVSS V3: 7.2 Severity: HIGH |
The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command. UCOPIA Wireless Appliance Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. UCOPIAWirelessAppliance is a wireless device from UCOPIA, France. A security vulnerability exists in the restricted shell interface in versions prior to UCOPIAWirelessAppliance 5.1.8
| VAR-201708-0816 | CVE-2017-11320 |
Technicolor TC7337 Router Cross-Site Scripting Vulnerability
Related entries in the VARIoT exploits database: VAR-E-201708-0138 |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router. Technicolor TC7337 The router contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. TechnicolorTC7337routers is a wireless router from Technicolor, France
| VAR-201709-0737 | CVE-2017-11351 | Axesstel MU553S Vulnerabilities related to the use of hard-coded credentials on devices |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account. Axesstel MU553S The device contains a vulnerability related to the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. AxesstelMU553S is a router from Axesstel, USA. An attacker could exploit the vulnerability to perform unauthorized operations. Axesstel MU553S is a router of Axesstel Company in the United States
| VAR-201708-1444 | CVE-2017-9247 | Sierra Wireless Windows Mobile Broadband Driver Package Vulnerabilities related to unquoted search paths or elements |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges. LenovoIdeaPadMiix510-12ISK and other are Lenovo's notebook products. SierraWirelessWANdriver is one of the wireless drivers for Sierra Wireless, Canada. A local attacker could exploit the vulnerability with an unreferenced service path to execute the file with administrator privileges. Lenovo IdeaPadMiix 510-12ISK, etc. The following products are affected: Lenovo IdeaPadMiix 510-12ISK; IdeaPadMiix 510-12IKB; ThinkPad L450; ThinkPad L460 Larue-2; ThinkPad L560; ThinkPad P40; ThinkPad P50; ThinkPad P50s;
| VAR-201707-0398 | CVE-2017-11361 | Inteno In the router "user" Vulnerability to read files by account |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
Inteno routers have a JUCI ACL misconfiguration that allows the "user" account to read files, write to files, and add root SSH keys via JSON commands to ubus. (Exploitation is sometimes easy because the "user" password might be "user" or might match the Wi-Fi key.). Intenorouters is a wireless router from IntenoBroadband Technologies of Sweden. A security vulnerability exists in the Inteno router that caused the program to fail to properly configure the JUCIACL
| VAR-201707-0387 | CVE-2017-11344 | plural ASUS For devices Asuswrt-Merlin Firmware and ASUS Firmware network map global buffer overflow vulnerability |
CVSS V2: 9.3 CVSS V3: 7.8 Severity: HIGH |
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response. ASUSRT-AC5300 and others are wireless routers from ASUS. A networkmap is one of the network diagram components. A buffer overflow vulnerability exists in networkmaps in several ASUS products
| VAR-201707-0400 | CVE-2017-11345 | plural ASUS For devices Asuswrt-Merlin Firmware and ASUS Firmware network map stack buffer overflow vulnerability |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response. ASUSRT-AC5300 and others are wireless routers from ASUS. A networkmap is one of the network diagram components. A buffer overflow vulnerability exists in networkmaps in several ASUS products
| VAR-201707-0391 | CVE-2017-11349 | dataTaker DT8x dEX Vulnerable to program or schedule creation |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data. Thermo Fisher Scientific dataTaker DT8x dEX is a data acquisition recorder from Thermo Fisher Scientific, Australia. A security vulnerability exists in version 1.72.007 of Thermo Fisher Scientific dataTaker DT8x dEX. A remote attacker can exploit this vulnerability to obtain plaintext configuration information
| VAR-201711-0222 | CVE-2017-2706 | Mate 9 Smartphone software path traversal vulnerability |
CVSS V2: 5.8 CVSS V3: 7.1 Severity: HIGH |
Mate 9 smartphones with software MHA-AL00AC00B125 have a directory traversal vulnerability in Push module. Since the system does not verify the file name during decompression, system directories are traversed. It could be exploited to cause the attacker to replace files and impact the service. Mate 9 Smartphone software contains a path traversal vulnerability.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. HuaweiMate9 is a smartphone from China's Huawei company. Pushmodule is one of the message push modules
| VAR-201711-0223 | CVE-2017-2707 | Mate 9 Vulnerabilities related to authorization, authority, and access control in smartphone software |
CVSS V2: 5.8 CVSS V3: 7.1 Severity: HIGH |
Mate 9 smartphones with software MHA-AL00AC00B125 have a privilege escalation vulnerability in Push module. An attacker tricks a user to save a rich media into message on the smart phone, which could be exploited to cause the attacker to delete message or fake user to send message. Mate 9 Smartphone software contains vulnerabilities related to authorization, permissions, and access control.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. HuaweiMate9 is a smartphone from China's Huawei company. Pushmodule is one of the message push modules
| VAR-201707-0300 | CVE-2017-2348 | Juniper Networks Junos OS Vulnerable to resource exhaustion |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Juniper Enhanced jdhcpd daemon may experience high CPU utilization, or crash and restart upon receipt of an invalid IPv6 UDP packet. Both high CPU utilization and repeated crashes of the jdhcpd daemon can result in a denial of service as DHCP service is interrupted. No other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS 14.1X53 prior to 14.1X53-D12, 14.1X53-D38, 14.1X53-D40 on QFX, EX, QFabric System; 15.1 prior to 15.1F2-S18, 15.1R4 on all products and platforms; 15.1X49 prior to 15.1X49-D80 on SRX; 15.1X53 prior to 15.1X53-D51, 15.1X53-D60 on NFX, QFX, EX. Juniper Networks Junos OS Contains a resource exhaustion vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. The operating system provides a secure programming interface and Junos SDK. A security vulnerability exists in Juniper Junos OS. A remote attacker can exploit this vulnerability to consume a large amount of CPU resources or cause the jdhcpd service to crash. The following releases are affected: Junos OS Release 14.1X53, Release 15.1, Release 15.1X49, Release 15.1X53
| VAR-201707-0298 | CVE-2017-2346 | Juniper Networks MX Run on the platform Junos OS Data processing vulnerability |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Application Layer Gateway (ALG). Repeated crashes of the Service PC can result in an extended denial of service condition. The issue can be seen only if NAT or stateful-firewall rules are configured with ALGs enabled. This issue was caused by the code change for PR 1182910 in Junos OS 14.1X55-D30, 14.1X55-D35, 14.2R7, 15.1R5, and 16.1R2. No other versions of Junos OS and no other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS on MX platforms running: 14.1X55 from 14.1X55-D30 to releases prior to 14.1X55-D35; 14.2R from 14.2R7 to releases prior to 14.2R7-S4, 14.2R8; 15.1R from 15.1R5 to releases prior to 15.1R5-S2, 15.1R6; 16.1R from 16.1R2 to releases prior to 16.1R3-S2, 16.1R4. Juniper MX Series is an MX series router product of Juniper Networks. Junos OS is a set of operating systems used in it. A security vulnerability exists in Junos OS in Juniper MX Series devices
| VAR-201707-0299 | CVE-2017-2347 | Juniper Networks Junos OS Input validation vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM is configured. Repeated crashes of the rpd daemon can result in an extended denial of service condition for the device. The affected releases are Junos OS 12.3X48 prior to 12.3X48-D50, 12.3X48-D55; 13.3 prior to 13.3R10; 14.1 prior to 14.1R4-S13, 14.1R8-S3, 14.1R9; 14.1X53 prior to 14.1X53-D42, 14.1X53-D50; 14.2 prior to 14.2R4-S8, 14.2R7-S6, 14.2R8; 15.1 prior to 15.1F2-S14, 15.1F5-S7, 15.1F6-S4, 15.1F7, 15.1R4-S7, 15.1R5-S1, 15.1R6; 15.1X49 prior to 15.1X49-D100; 15.1X53 prior to 15.1X53-D105, 15.1X53-D47, 15.1X53-D62, 15.1X53-D70; 16.1 prior to 16.1R3-S3, 16.1R4. No other Juniper Networks products or platforms are affected by this issue. Juniper Networks Junos OS Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Juniper Junos is prone to a denial-of-service vulnerability. This issue could be exploited to execute arbitrary code; however, this has not been confirmed. The operating system provides a secure programming interface and Junos SDK. The following releases are affected: Junos OS Release 12.3X48, Release 13.3, Release 14.1, Release 14.1X53, Release 14.2, Release 15.1, Release 15.1X49, Release 15.1X53, Release 16.1