VARIoT IoT vulnerabilities database
| VAR-201707-0922 | CVE-2017-6712 | Cisco Elastic Services Controller On the server in certain commands root Vulnerabilities with elevated privileges |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in certain commands of Cisco Elastic Services Controller could allow an authenticated, remote attacker to elevate privileges to root and run dangerous commands on the server. The vulnerability occurs because a "tomcat" user on the system can run certain shell commands, allowing the user to overwrite any file on the filesystem and elevate privileges to root. This vulnerability affects Cisco Elastic Services Controller prior to releases 2.3.1.434 and 2.3.2. Cisco Bug IDs: CSCvc76634.
An attacker can exploit this issue to execute arbitrary command on the affected system. This may aid in further attacks
| VAR-201707-0905 | CVE-2017-6733 | Cisco ISE Portal Web -Based application interface vulnerabilities in stored cross-site scripting |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
A vulnerability in the web-based application interface of the Cisco Identity Services Engine (ISE) portal could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvd87482. Known Affected Releases: 2.1(102.101) 2.2(0.283) 2.3(0.151).
Successful exploits will result in the execution of arbitrary attacker-supplied HTML and script code in the context of the affected application, potentially allowing the attacker to steal cookie-based authentication credentials or control how the page is rendered to the user. Other attacks are also possible.
This issue is being tracked by Cisco Bug ID CSCvd87482. The platform monitors the network by collecting real-time information on the network, users and devices, and formulating and implementing corresponding policies. A remote attacker can exploit this vulnerability to execute arbitrary code by intercepting user data packets and injecting malicious code
| VAR-201711-1028 | CVE-2017-8213 | Huawei SMC2.0 Certificate validation vulnerability in other software |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
Huawei SMC2.0 with software of V100R003C10, V100R005C00SPC100, V100R005C00SPC101B001T, V100R005C00SPC102, V100R005C00SPC103, V100R005C00SPC200, V100R005C00SPC201T, V500R002C00, V600R006C00 has an input validation vulnerability when handle TLS and DTLS handshake with certificate. Due to the insufficient validation of received PKI certificates, remote attackers could exploit this vulnerability to crash the TLS module. Multiple Huawei products are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition. Huawei SMC2.0 is a set of video management solutions of China Huawei (Huawei). The solution supports H.323 and SIP two mainstream protocols at the same time, and supports the access of devices such as computers and mobile phones. The following versions are affected: Huawei SMC2.0 V100R003C10 Version, V100R005C00SPC100 Version, V100R005C00SPC101B001T Version, V100R005C00SPC102 Version, V100R005C00SPC103 Version, V100R005C00SPC200 Version, V100R005C00SPC201T Version, V500R002C00 Version, V600R006C00 Version
| VAR-201707-0586 | CVE-2017-0706 | Android of Broadcom Wi-Fi Vulnerability that could elevate privileges in drivers |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: MEDIUM |
A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532. Google Android is prone to multiple security vulnerabilities.
An attacker can leverage these issues to execute arbitrary code and gain elevated privileges. Failed exploit attempts may result in a denial of service condition
| VAR-201707-1350 | No CVE | HP Photosmart 5520 series printer has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HP Photosmart 5520 series is a mid-range inkjet printer.
The HP Photosmart 5520 series printer has an unauthorized access vulnerability. Allows an attacker to use the vulnerability to enter the background of the printer, view sensitive information, or perform unauthorized operations.
| VAR-201707-1349 | No CVE | SNMP Protocol Community String Authentication Bypass Vulnerability in Lenovo NetPower V Firewall |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Lenovo PowerV Firewall is a comprehensive UTM that integrates firewall, IPSec VPN, SSL VPN, intrusion detection and protection system, antivirus, vulnerability scanning, active defense, flow control, log audit, and centralized management.
Lenovo NetPower V firewall has SNMP protocol community string authentication permission bypass vulnerability, allowing attackers to use arbitrary strings or integer values to bypass SNMP access control and write arbitrary strings in MIB (Management Information Base) To get sensitive information about the device.
| VAR-201707-0335 | CVE-2017-2244 | Brother Industries MFC-J960DWN Cross-Site Request Forgery Vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. MFC-J960DWN provided by BROTHER INDUSTRIES, LTD. is a MultiFunction Printer. MFC-J960DWN contains a cross-site request forgery vulnerability (CWE-352). Taiga Asano reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.If a user views a malicious page, unintended operations such as changing settings of the device may be performed. A remote attacker could exploit this vulnerability to perform unauthorized operations
| VAR-201711-0935 | CVE-2017-8172 | Huawei P10 Plus and P10 Vulnerability related to array index verification in smartphones |
CVSS V2: 7.1 CVSS V3: 5.5 Severity: MEDIUM |
Isub service in P10 Plus and P10 smart phones with earlier than VKY-AL00C00B157 versions and earlier than VTR-AL00C00B157 versions has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and the application can send given parameter to specific interface, which make a out-of-bounds array access that results in smart phone restart. HuaweiVicky-AL00A and Victoria-AL00A are both Huawei's smartphone devices. The vulnerability stems from the program not fully performing input verification. Multiple Huawei products are prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to crash the system, denying service to legitimate users
| VAR-201709-0218 | CVE-2017-10793 | AT&T U-verse Information disclosure vulnerability in firmware |
CVSS V2: 4.3 CVSS V3: 8.1 Severity: HIGH |
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows remote attackers to obtain sensitive information (such as the Wi-Fi password) by leveraging knowledge of a hardware identifier, related to the Bulk Data Collection (BDC) mechanism defined in Broadband Forum technical reports. AT&T U-verse Firmware contains an information disclosure vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. ArrisNVG589 and NVG599 are router products of Arris Group of the United States. AT&TU-verse is the firmware used in it. A security vulnerability exists in the AT&TU-verse9.2.2h0d83 version of ArrisNVG589 and NVG599. A remote attacker can exploit this vulnerability to obtain sensitive information (for example, a Wi-Fi password). AT&T U-verse Arris Modems are prone to following security vulnerabilities:
1.
2. An information-disclosure vulnerability
3. A command injection vulnerability
4. Failed exploit attempts may result in a denial-of-service condition
| VAR-201707-1356 | No CVE | HP Officejet Pro X451dw Printer has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HP Officejet Pro X451dw is a desktop printer from Hewlett-Packard.
The HP Officejet Pro X451dw Printer has an unauthorized access vulnerability. An attacker could use the vulnerability to gain unauthorized access to the configuration page and obtain sensitive information.
| VAR-201707-0931 | CVE-2017-8116 | Teltonika RUT9XX In the router firmware management interface root Vulnerability to execute arbitrary commands with privileges |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request. TeltonikaRUT9XXrouters (also known as LuCI) is a router product from Teltonika, Lithuania. A security vulnerability exists in the management interface in the TeltonikaRUT9XX router using firmware 0.03.265 and earlier. Teltonika Routers are prone to a remote command-execution vulnerability because it fails to properly sanitize user-supplied input. This may aid in further attacks
| VAR-201707-0197 | CVE-2017-10796 | TP-Link NC250 Vulnerability to display video and audio without authentication in device firmware |
CVSS V2: 3.3 CVSS V3: 6.5 Severity: MEDIUM |
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL. TP-LinkNC250 is a network camera product of China TP-LINK. TP-LINKNC250 has a certification bypass vulnerability. TP-Link NC250 with 1.2.1 build 170515 and earlier firmware has a security vulnerability
| VAR-201804-0472 | CVE-2016-8732 | Invincea Dell Protected Workspace Permissions vulnerability |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn off some of the protection mechanisms provided by the Invincea product. Invincea Dell Protected Workspace Contains a permission vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Dell is a company based in Round Rock, Texas, USA. There are protection bypass bugs in several Dell products. An attacker could exploit the vulnerability to bypass the authentication mechanism and gain unauthorized access. A privilege escalation vulnerability.
2
| VAR-201804-0459 | CVE-2016-9038 | Invincea-X Race condition vulnerability |
CVSS V2: 4.4 CVSS V3: 7.8 Severity: HIGH |
An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result in kernel memory corruption, which could result in privilege escalation. An attacker needs to execute a special application locally to trigger this vulnerability. Invincea-X Contains a race condition vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Dell is a company based in Round Rock, Texas, USA. A number of Dell product privilege escalation vulnerabilities. Allows an attacker to exploit the vulnerability to escalate privileges.
2. Multiple security bypass vulnerabilities
An attacker may leverage these issues to execute arbitrary code in the context of the vulnerable application to elevate privilege and bypass the authentication mechanism and gain unauthorized access
| VAR-201804-0552 | CVE-2017-2802 | Dell Precision Optimizer Software unreliable search path vulnerability |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
An exploitable dll hijacking vulnerability exists in the poaService.exe service component of the Dell Precision Optimizer software version 3.5.5.0. A specifically named malicious dll file located in one of directories pointed to by the PATH environment variable will lead to privilege escalation. An attacker with local access to vulnerable system can exploit this vulnerability. Dell Precision Optimizer The software contains an unreliable search path vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Dell is a company based in Round Rock, Texas, USA. A number of Dell products have security bypass vulnerabilities. A privilege escalation vulnerability.
2. The tool supports automatic adjustment of system settings such as Intel Hyper-Threading, number of CPU cores, processor priority, graphics card, and power supply
| VAR-201708-0403 | CVE-2017-10677 | Linksys EA4500 Device firmware cross-site request forgery vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP. CiscoLinksysEA4500devices is a router device from Cisco. A remote attacker could exploit this vulnerability to perform unauthorized operations
| VAR-201706-1134 | No CVE | TerraMaster NAS TOS arbitrary command execution vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
TerraMaster is a high-end professional storage development and sales company headquartered in New York, USA, has more than 16 years of history, is a famous professional storage brand in the United States. A security vulnerability exists in TerraMasterNASTOS version 3.0.30 and below. Allows an attacker to exploit a vulnerability without any command to log in to authorize execution.
| VAR-201706-1114 | No CVE | Struts2-045 Remote Code Execution Vulnerability in Zhejiang Dahua DSS 3.0 Security Platform |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
DSS (Digital Surveillance System) is a highly integrated and powerful digital monitoring management system developed by Zhejiang Dahua Technology Co., Ltd.
Zhejiang Dahua's new DSS 3.0 security platform uses Apache Struts 2 as the website application framework. Because the software has a remote code execution high-risk vulnerability, attackers can use the vulnerability to gain remote control of the web server host.
| VAR-201706-1136 | No CVE | Ruijie RG-WALL-160S firewall has SNMP protocol community string authentication permission bypass vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
RG-WALL 160S is a 100M firewall product launched by Ruijie Networks.
The Ruijie RG-WALL-160S firewall has an SNMP protocol community string authentication permission bypass vulnerability. Allows an attacker to use arbitrary strings or integer values to bypass SNMP access control and write arbitrary strings in the MIB (Management Information Base) to obtain sensitive information of the device
| VAR-201706-1152 | No CVE | Cross-site Scripting Vulnerability in multiple Hitachi products |
CVSS V2: 4.3 CVSS V3: 4.7 Severity: Medium |
A cross-site scripting vulnerability was found in uCosminexus Portal Framework, Groupmax Collaboration, Hitachi Navigation Platform and JP1/Navigation Platform. Remote users can exploit this vulnerability to execute malicious scripts.