VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201707-0857 CVE-2017-11589 plural Cisco Residential Gateway Vulnerabilities related to authorization, authority, and access control in products CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Cisco DDR2200 ADSL2+ Residential Gateway and DDR2201v1 ADSL2+ Residential Gateway Devices have vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Cisco DDR2200ADSL2+ResidentialGateway and DDR2201v1ADSL2+ResidentialGateway are home wireless gateway devices from Cisco. The Cisco DDR2200ADSL2+ResidentialGatewayDDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1ADSL2+ResidentialGatewayDDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices have an authentication bypass vulnerability in the device due to lack of access control. An attacker could exploit the vulnerability to gain access to a page. Multiple Cisco ADSL Routers are prone to a multiple authentication-bypass vulnerabilities. An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. The program lacks access controls
VAR-201707-0296 CVE-2017-2344 Junos OS Buffer error vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A routine within an internal Junos OS sockets library is vulnerable to a buffer overflow. Malicious exploitation of this issue may lead to a denial of service (kernel panic) or be leveraged as a privilege escalation through local code execution. The routines are only accessible via programs running on the device itself, and veriexec restricts arbitrary programs from running on Junos OS. There are no known exploit vectors utilizing signed binaries shipped with Junos OS itself. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67; 12.3X48 prior to 12.3X48-D51, 12.3X48-D55; 13.3 prior to 13.3R10-S2; 14.1 prior to 14.1R2-S10, 14.1R8-S4, 14.1R9; 14.1X50 prior to 14.1X50-D185; 14.1X53 prior to 14.1X53-D122, 14.1X53-D45, 14.1X53-D50; 14.2 prior to 14.2R4-S9, 14.2R7-S7, 14.2R8; 15.1 prior to 15.1F2-S18, 15.1F6-S7, 15.1R4-S8, 15.1R5-S5, 15.1R6-S1, 15.1R7; 15.1X49 prior to 15.1X49-D100; 15.1X53 prior to 15.1X53-D231, 15.1X53-D47, 15.1X53-D48, 15.1X53-D57, 15.1X53-D64, 15.1X53-D70; 16.1 prior to 16.1R3-S4, 16.1R4-S3, 16.1R4-S4, 16.1R5; 16.2 prior to 16.2R2; 17.1 prior to 17.1R1-S3, 17.1R2; 17.2 prior to 17.2R1-S1, 17.2R2; 17.2X75 prior to 17.2X75-D30. No other Juniper Networks products or platforms are affected by this issue. Junos OS Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Juniper Junos is prone to a local buffer-overflow vulnerability. Successful exploits may allow attackers to execute arbitrary code in the context of the application or gain elevated privileges. Failed exploits may result in denial-of-service conditions. The operating system provides a secure programming interface and Junos SDK
VAR-201707-0297 CVE-2017-2345 Junos OS Input validation vulnerability CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and restart by sending a crafted SNMP packet. Repeated crashes of the snmpd daemon can result in a partial denial of service condition. Additionally, it may be possible to craft a malicious SNMP packet in a way that can result in remote code execution. SNMP is disabled in Junos OS by default. Junos OS devices with SNMP disabled are not affected by this issue. No other Juniper Networks products or platforms are affected by this issue. NOTE: This is a different issue than Cisco CVE-2017-6736, CVE-2017-6737, and CVE-2017-6738. Affected releases are Juniper Networks Junos OS 12.1X46 prior to 12.1X46-D67; 12.3X48 prior to 12.3X48-D51, 12.3X48-D55; 13.3 prior to 13.3R10-S2; 14.1 prior to 14.1R2-S10, 14.1R8-S4, 14.1R9; 14.1X50 prior to 14.1X50-D185; 14.1X53 prior to 14.1X53-D122, 14.1X53-D44, 14.1X53-D50; 14.2 prior to 14.2R4-S9, 14.2R7-S7, 14.2R8; 15.1 prior to 15.1F2-S18, 15.1F6-S7, 15.1R4-S8, 15.1R5-S5, 15.1R6-S1, 15.1R7; 15.1X49 prior to 15.1X49-D100, 15.1X49-D110; 15.1X53 prior to 15.1X53-D231, 15.1X53-D47, 15.1X53-D48, 15.1X53-D57, 15.1X53-D64, 15.1X53-D70; 16.1 prior to 16.1R3-S4, 16.1R4-S3, 16.1R4-S4, 16.1R5; 16.2 prior to 16.2R2, 16.2R3; 17.1 prior to 17.1R1-S3, 17.1R2, 17.1R3; 17.2 prior to 17.2R1-S1, 17.2R2; 17.2X75 prior to 17.2X75-D30. Junos releases prior to 10.2 are not affected. Junos OS Contains an input validation vulnerability. This vulnerability is CVE-2017-6736 , CVE-2017-6737 ,and CVE-2017-6738 This is a different vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. Juniper Junos is prone to a denial-of-service vulnerability. Attackers can exploit this issue to cause the snmpd daemon to crash and restart the affected device, denying service to legitimate users. This issue could be exploited to execute arbitrary code; however, this has not been confirmed. The operating system provides a secure programming interface and Junos SDK
VAR-201707-0276 CVE-2017-3754 Part of Lenovo Of brand notebook products BIOS Vulnerabilities related to security functions CVSS V2: 7.2
CVSS V3: 6.7
Severity: MEDIUM
Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical or administrative access to a system to be able to flash the BIOS with an arbitrary image and potentially run malicious BIOS code. Part of Lenovo Of brand notebook products BIOS Contains vulnerabilities related to security features.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Lenovo 320-17AST, etc. are all computer products of China Lenovo (Lenovo). BIOS is one of the basic input input systems. There are security vulnerabilities in the BIOS of several Lenovo products. The following versions are affected: Lenovo 320-17AST; 710s-13IKB/XiaoXin Air 13IKB; 710S-13ISK/XiaoXin Air 13; K21-80; K22-80/Lenovo V720-12; K41-80; ideapad 110-14AST; ideapad 110 -15AST; ideapad 320-14AST; ideapad 320-15AST; XiaoXin Rui7000; MIIX 710-12IKB; MIIX 720-12IKB; Rescuer E520-15IKB; V110-14IAP; 11 IKB
VAR-201707-0301 CVE-2017-2349 Juniper Networks SRX Runs on series devices Junos OS of IDP Command injection vulnerability in functionality CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allows a user with login access to the device to execute shell commands and elevate privileges. Affected releases are Juniper Networks Junos OS 12.1X44 prior to 12.1X44-D60; 12.1X46 prior to 12.1X46-D50; 12.1X47 prior to 12.1X47-D30, 12.1X47-D35; 12.3X48 prior to 12.3X48-D20, 12.3X48-D30; 15.1X49 prior to 15.1X49-D20, 15.1X49-D30. Juniper Junos is prone to a remote command-injection vulnerability. An attacker can exploit this issue to execute arbitrary shell commands on the affected system with elevated privileges. This may aid in further attacks. Juniper MX Series is an MX series router product of Juniper Networks. Junos OS is a set of operating systems used in it
VAR-201707-0242 CVE-2017-10603 Junos OS CLI In XML Injection vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos OS 15.1X53 prior to 15.1X53-D47, 15.1 prior to 15.1R3. Junos versions prior to 15.1 are not affected. No other Juniper Networks products or platforms are affected by this issue. Juniper Junos is prone to a local privilege-escalation vulnerability. Local attackers could exploit this issue to run arbitrary commands with root privileges. The operating system provides a secure programming interface and Junos SDK
VAR-201807-2225 No CVE OSIsoft PI ProcessBook and PI ActiveView Arbitrary code execution vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
PI-ProcessBook is a powerful tool for displaying real-time data collected and stored by PI systems. PI-ActiveView is a Miscellaneous Shareware software. A remote code execution vulnerability exists in several OSIsoft PI products. An attacker could exploit this vulnerability to execute arbitrary code in the context of a user running in an affected application, and a failed attack would result in a denial of service. Failed exploit attempts will likely cause a denial-of-service condition. The following products are vulnerable: PI ProcessBook 2015 R2 3.6.0 and prior PI ActiveView 2015 R2 3.6.0 and prior
VAR-201708-1515 CVE-2017-9938 Siemens SIMATIC Logon Input validation vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition. The service restarts automatically. Siemens SIMATIC Logon Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. SIMATIC Logon is automation software. Siemens SIMATIC Logon is prone to a denial-of-service vulnerability. A remote attacker can exploit this issue to cause a denial-of-service condition. Due to the nature of this issue, code execution may be possible but this has not been confirmed. SIMATIC Logon versions prior to 1.6 are vulnerable
VAR-201708-1396 CVE-2017-7916 ABB VSN300 WiFi Logger Card and VSN300 WiFi Logger Card for React Vulnerabilities related to authorization, permissions, and access control CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted. An authentication-bypass vulnerability 2. A security-bypass vulnerability An attacker can exploit these issues to bypass certain security restrictions, perform certain unauthorized actions and bypass the authentication mechanism
VAR-201707-1361 No CVE Bako Travel Android App Has Any User Password Reset Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Bago Travel is a car time-sharing and sharing platform created by Beijing Bago Car Leasing Co., Ltd. With the help of the Internet of Things technology and advanced operation model, it realizes an unattended, rent-and-pay smart car usage method, and is committed to providing users with Provide 24-hour safe, convenient and economical car service, improve urban travel efficiency, reduce congestion and emissions, and build a beautiful travel experience. There is an arbitrary user password reset vulnerability in the Android app of Ba Ge Travel. An attacker can use this vulnerability to reset their password arbitrarily.
VAR-201707-1346 No CVE D-Link DIR-100 Cross-Site Request Forgery Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The D-LinkDIR-100 is a small broadband router with integrated firewall capabilities. A cross-site request forgery vulnerability exists in D-LinkDIR-1001.01. Allows remote attackers to build malicious URIs, entice users to resolve, and perform malicious actions in the target user context.
VAR-201707-1365 No CVE SAP Netweaver Data Orchestration Engine Unspecified Information Disclosure Vulnerability CVSS V2: -
CVSS V3: -
Severity: -
SAP Netweaver Data Orchestration Engine is prone to an unspecified information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
VAR-201707-1367 No CVE SAP NetWeaver Master Data Management Information Disclosure Vulnerability CVSS V2: -
CVSS V3: -
Severity: -
SAP NetWeaver is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
VAR-201711-0979 CVE-2017-8141 Huawei P10 Plus Vulnerability related to double release in smartphone software CVSS V2: 9.3
CVSS V3: 7.8
Severity: HIGH
The Touch Panel (TP) driver in P10 Plus smart phones with software versions earlier than VKY-AL00C00B153 has a memory double free vulnerability. An attacker with the root privilege of the Android system tricks a user into installing a malicious application, and the application can start multiple threads and try to free specific memory, which could triggers double free and causes a system crash or arbitrary code execution. Huawei P10 Plus Smartphone software contains a double release vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. HuaweiP10Plus is a Huawei smartphone device from China. There is a memory duplication release vulnerability in the touchscreen driver of the HuaweiP10Plus phone
VAR-201707-1217 CVE-2017-7730 iSmartAlarm cube Vulnerability related to input validation on devices CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will stop responding. iSmartAlarm cube The device contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. An attacker could use this vulnerability to cause a denial of service (device stops responding)
VAR-201711-0725 CVE-2017-11169 iBall iB-WRA300N3GT Vulnerabilities related to authorization, authority, and access control in devices CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter to /form2userconfig.cgi. iBall iB-WRA300N3GT Devices have vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The iBalliB-WRA300N3GT is a wireless router product from iBall India. An elevation of privilege vulnerability exists in iBalliB-WRA300N3GT with iB-WRA300N3GT_1.1.1 firmware. A remote attacker can exploit this vulnerability to gain root privileges
VAR-201707-1215 CVE-2017-7728 iSmartAlarm cube Cryptographic vulnerabilities in devices CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
On iSmartAlarm cube devices, there is authentication bypass leading to remote execution of commands (e.g., setting the alarm on/off), related to incorrect cryptography. iSmartAlarm cube The device contains cryptographic vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. iSmartAlarmcubedevices is a smart home device from iSmartAlarm. An authentication bypass vulnerability exists in the iSmartAlarmcube device. A remote attacker can exploit the vulnerability to execute commands
VAR-201707-1216 CVE-2017-7729 iSmartAlarm cube Device Access Control Error Vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext. iSmartAlarmcubedevices is a smart home device from iSmartAlarm. There are currently no detailed details of the vulnerability provided
VAR-201707-0616 CVE-2017-11165 dataTaker DT80 dEX Vulnerable to obtaining important authentication and configuration information CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI. Thermo Fisher Scientific dataTaker DT80 dEX is a data acquisition recorder from Thermo Fisher Scientific, Australia. A security vulnerability exists in version 1.50.012 of the Thermo Fisher Scientific dataTaker DT80 dEX
VAR-201707-0990 CVE-2017-8011 plural EMC Vulnerabilities related to the use of hard-coded credentials in products CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all versions, EMC M&R (Watch4Net) for SAS Solution Packs all versions) contain undocumented accounts with default passwords for Webservice Gateway and RMI JMX components. A remote attacker with the knowledge of the default password may potentially use these accounts to run arbitrary web service and remote procedure calls on the affected system. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Dell EMC VNX Monitoring and Reporting. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.The specific flaw exists within the Scheduler class. An attacker can use the static credentials to access VNX Webservice Gateway service's API to execute arbitrary code under the context of SYSTEM. Multiple EMC Products are prone to an insecure default-password vulnerability. Remote attackers with knowledge of the default credentials may exploit this vulnerability to gain unauthorized access and perform unauthorized actions. This may aid in further attacks. Resolution: Customers are strongly advised to change any default passwords for Webservice Gateway and RMI JMX components. * EMC ViPR SRM and EMC Storage M&R customers should refer to the EMC M&R Platform 6.8 Security Configuration Guide (part of the EMC ViPR SRM 4.1 documentation, found at https://community.emc.com/docs/DOC-59221) for the procedure to modify default passwords * EMC M&R (Watch4Net) for SAS Solution Packs customers should refer to the knowledgebase article below for the procedure to modify default passwords: https://support.emc.com/kb/501588 * EMC VNX M&R customers should refer to the knowledgebase article below for the procedure to modify default passwords: https://support.emc.com/kb/501419 Link to remedies: Credits: EMC would like to thank rgod working with Trend Micro's Zero Day Initiative for reporting this vulnerability. [The following is standard text included in all security advisories. Please do not change or delete.] Read and use the information in this EMC Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact EMC Software Technical Support at 1-877-534-2867. For an explanation of Severity Ratings, refer to EMC Knowledgebase solution emc218831. EMC recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability. EMC recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. EMC disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall EMC or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if EMC or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJZZSKkAAoJEHbcu+fsE81ZCHUH/0XvP8+rUcE7d4SljEpl8Ayd 3YMeSnak8CPcHAJq6xTWjDt8KnBlwwSaeAvBap0akxF/sqnnOOk7wLDBuc9kDt7y yp1DgiGgLOlVv5s8kAPCnJ0b7JkszrZ8mleJnqWBohKYUhlPeNTOj+x/NBmBoEWN fFvQ/deN2ArzRyz4XYDMbEfJFe2f8hSCg9YjZpdMi0nTRlRn6WRxgX5kwKjh2w6I tKakT0UGyOPv3VUaolDrCTegvt4BeBeQzeEZmlP0IEWeVmLLRgrpH4k8Dle9K+l5 BVDI2QFcg++CS5L1KPdZr+OVSOVUhdX6MtWlShAvZrxQ54zGf237fubsNJd6V6U= =iu/j -----END PGP SIGNATURE-----