VARIoT IoT vulnerabilities database
| VAR-201706-1151 | No CVE | Multiple Vulnerabilities in Hitachi IT Operations Director and JP1/IT Desktop Management |
CVSS V2: 7.5 CVSS V3: 8.1 Severity: High |
A cross-site scripting and an XML external entity (XXE) vulnerability have been found in Hitachi IT Operations Director, JP1/IT Desktop Management - Manager and JP1/IT Desktop Management 2 - Manager.An attacker may conduct a cross-site scripting attack and a XML external entity (XXE) attack.
| VAR-201706-0247 | CVE-2017-10709 | Elephone P9000 Runs on the device Android Vulnerabilities related to security functions in the lock screen |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: MEDIUM |
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess. Android is a Linux-based open source operating system jointly developed by Google and the Open Handheld Device Alliance (OHA). ElephoneP9000 is a smartphone running the Android operating system from Elephone China. Lockscreen is one of the screen lock components. There is a security hole in the lockscreen in the Android 6.0 version of the ElephoneP9000. An attacker with a physical location nearby can use the vulnerability to bypass the error PIN code blocking feature by entering the PIN code and holding the backspace key
| VAR-201707-0165 | CVE-2017-10676 | D-Link DIR-600M Device Cross-Site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
On D-Link DIR-600M devices before C1_v3.05ENB01_beta_20170306, XSS was found in the form2userconfig.cgi username parameter. D-Link DIR-600M Device form2userconfig.cgi Contains a cross-site scripting vulnerability.username A cross-site scripting attack may be performed via parameters. D-LinkDIR-600M is a wireless router product of D-Link. A remote attacker can exploit this vulnerability to brute force passwords
| VAR-201706-0045 | CVE-2015-9105 | Synology Video Station Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos. Synology Video Station is a video manager from Synology
| VAR-201706-0044 | CVE-2015-9104 | Synology Audio Station Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the album title. Synology Audio Station is an audio manager from Synology. A cross-site scripting vulnerability exists in Synology Audio Station 5.1 prior to 5.1-2550 and 5.4 prior to 5.4-2857
| VAR-201706-0043 | CVE-2015-9103 | Synology Note Station Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments. Synology Note Station is a cloud-based note management platform from Synology
| VAR-201706-0042 | CVE-2015-9102 | Synology Photo Station Vulnerable to cross-site scripting |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos. Synology Photo Station is a set of solutions for sharing pictures, videos and blogs on the Internet from Synology, a Taiwan-based company
| VAR-201707-0938 | CVE-2017-9980 | Green Packet DX-350 of Web In the interface "PING" Command insertion vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter. The GreenPacketDX-350 is a network access point device from GreenPacket, USA. There is a security hole in the PING function of the web interface in the GreenPacketDX-350. An attacker can use this vulnerability to inject commands with the help of the \342\200\230pip\342\200\231 parameter
| VAR-201706-0359 | CVE-2017-3749 | Lenovo VIBE cell phone's Idea Friend Android Vulnerabilities related to authorization, authority, and access control in applications |
CVSS V2: 6.9 CVSS V3: 6.4 Severity: MEDIUM |
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750. Lenovo VIBE cell phone's Idea Friend Android Applications have vulnerabilities related to authorization, permissions, and access control.CVE-2017-3748 and CVE-2017-3750 Information is obtained, information is tampered with, and service operation is disrupted by exploiting it together with vulnerabilities (DoS) There is a possibility of being put into a state. Android6.0Marshmallow is a Linux-based open source operating system jointly developed by Google and the Open Handheld Device Alliance (OHA). LenovoA2010-a, etc. are all Lenovo's smartphone products using the Android6.0 Marshmallow operating system. A privilege escalation vulnerability exists in several LenovoVIBE phones using versions prior to Android6.0 Marshmallow, which stems from the IdeaFriendAndroid app allowing backup and storage of private data via AndroidDebugBridge. An attacker could exploit the vulnerability to gain elevated privileges
| VAR-201706-0360 | CVE-2017-3750 | Lenovo VIBE cell phone's Lenovo Security Android Vulnerabilities related to authorization, authority, and access control in applications |
CVSS V2: 6.9 CVSS V3: 6.4 Severity: MEDIUM |
On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3749. Lenovo VIBE cell phone's Lenovo Security Android Applications have vulnerabilities related to authorization, permissions, and access control.CVE-2017-3748 and CVE-2017-3749 Information is obtained, information is tampered with, and service operation is disrupted by exploiting it together with vulnerabilities (DoS) There is a possibility of being put into a state. Android6.0Marshmallow is a Linux-based open source operating system jointly developed by Google and the Open Handheld Device Alliance (OHA). LenovoA2010-a, etc. are all Lenovo's smartphone products using the Android6.0 Marshmallow operating system. A Permission Access Vulnerability exists in several LenovoVIBE phones using versions prior to Android6.0 Marshmallow, which stems from the LenovoSecurityAndroid app allowing backup and storage of private data via AndroidDebugBridge. An attacker could exploit the vulnerability to gain elevated privileges
| VAR-201706-0461 | CVE-2017-6036 | Belden Hirschmann GECKO Lite Managed Server-side request forgery vulnerability in switch |
CVSS V2: 4.3 CVSS V3: 6.5 Severity: MEDIUM |
A Server-Side Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web server receives a request, but does not sufficiently verify that the request is being sent to the expected destination. BeldenHirschmannGECKO is a streamlined managed industrial Ethernet switch. The vulnerability stems from a program that failed to adequately verify the request. An attacker could exploit the vulnerability to gain sensitive information by accessing a copy of the configuration file. The vulnerability is caused by the program's insufficient verification of requests
| VAR-201706-0462 | CVE-2017-6038 | Belden Hirschmann GECKO Cross-Site Request Forgery Vulnerability |
CVSS V2: 5.8 CVSS V3: 7.1 Severity: HIGH |
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request. BeldenHirschmannGECKO is a streamlined managed industrial Ethernet switch. The vulnerability stems from a program that failed to adequately verify the request. An attacker could exploit the vulnerability to perform unauthorized operations
| VAR-201706-0464 | CVE-2017-6040 | Belden Hirschmann GECKO Information Disclosure Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive information can be obtained anonymously. BeldenHirschmannGECKO is a streamlined managed industrial Ethernet switch
| VAR-201707-1052 | CVE-2017-6736 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload.
Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable.
There are workarounds that address these vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
| VAR-201707-0930 | CVE-2017-6737 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability. Cisco IOS and IOS XE Software are prone to multiple remote code-execution vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable
| VAR-201707-0962 | CVE-2017-6738 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload.
Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable.
There are workarounds that address these vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
| VAR-201707-0958 | CVE-2017-6739 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability. Cisco IOS and IOS XE Software are prone to multiple remote code-execution vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable
| VAR-201707-0959 | CVE-2017-6740 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities.
The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload.
Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable.
There are workarounds that address these vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
| VAR-201707-0963 | CVE-2017-6741 | Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability. Cisco IOS and IOS XE Software are prone to multiple remote code-execution vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
| VAR-201707-0964 | CVE-2017-6742 | Cisco IOS and IOS XE of SNMP Vulnerabilities in subsystems that could allow remote code execution on affected systems |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the SNMP implementation of could allow an authenticated, remote attacker to cause a reload of the affected system or to remotely execute code. An attacker could exploit this vulnerability by sending a crafted SNMP packet to the affected device.
The vulnerability is due to a buffer overflow in the affected code area. The vulnerability affects all versions of SNMP (versions 1, 2c, and 3). The attacker must know the SNMP read only community string (SNMP version 2c or earlier) or the user credentials (SNMPv3). An exploit could allow the attacker to execute arbitrary code and obtain full control of the system or to cause a reload of the affected system.
Only traffic directed to the affected system can be used to exploit this vulnerability. Cisco IOS and IOS XE Software are prone to multiple remote code-execution vulnerabilities.
These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable