VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201707-0965 CVE-2017-6743 Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities. These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
VAR-201707-0960 CVE-2017-6744 Cisco IOS and IOS XE of SNMP Subsystem vulnerable to remote code execution on affected systems CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only traffic directed to an affected system can be used to exploit these vulnerabilities. The vulnerabilities are due to a buffer overflow condition in the SNMP subsystem of the affected software. The vulnerabilities affect all versions of SNMP - Versions 1, 2c, and 3. To exploit these vulnerabilities via SNMP Version 2c or earlier, the attacker must know the SNMP read-only community string for the affected system. To exploit these vulnerabilities via SNMP Version 3, the attacker must have user credentials for the affected system. A successful exploit could allow the attacker to execute arbitrary code and obtain full control of the affected system or cause the affected system to reload. Customers are advised to apply the workaround as contained in the Workarounds section below. Fixed software information is available via the Cisco IOS Software Checker. All devices that have enabled SNMP and have not explicitly excluded the affected MIBs or OIDs should be considered vulnerable. There are workarounds that address these vulnerabilities. These issues are being tracked by Cisco Bug IDs-CSCve54313,CSCve57697,CSCve60276,CSCve60376,CSCve60402,CSCve60507,CSCve66540,CSCve66601,CSCve66658,CSCve78027,CSCve89865. Simple Network Management Protocol (SNMP) subsystem is one of the simple network management subsystems used for network device management information exchange
VAR-201706-1146 No CVE Huawei Y6 Pro graphics Driver Memory Leak Vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
HuaweiY6Pro is a smartphone from China's Huawei company. A memory leak vulnerability exists in the Huawei Y6Pro mobile phone graphics driver using the MTK platform. Due to insufficient input verification, the attacker lured the user to install a malicious application that obtained the system privileges of the Android system. The application can use this vulnerability to send specific parameters to the mobile phone driver, resulting in memory leaks.
VAR-201706-1148 No CVE Huawei Y6 Pro graphics Driver Buffer Overflow Vulnerability CVSS V2: 7.2
CVSS V3: -
Severity: HIGH
HuaweiY6Pro is a smartphone from China's Huawei company. A buffer overflow vulnerability exists in the Huawei Y6Pro mobile phone graphics driver using the MTK platform. Due to insufficient input verification, the attacker lured the user to install a malicious application that obtained the system privileges of the Android system. The application can use the vulnerability to send specific parameters to the mobile phone driver, resulting in system restart or privilege escalation.
VAR-201711-0980 CVE-2017-8142 Huawei Mate 9 and Mate 9 Pro Vulnerability related to the use of released memory in smartphone software CVSS V2: 9.3
CVSS V3: 7.8
Severity: HIGH
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user into installing a malicious application, and the application can start multiple threads and try to create and free specific memory, which could triggers access memory after free it and causes a system crash or arbitrary code execution. Mate9 and Mate9Pro are smart phones from China's Huawei company. Trusted Execution Environment TEE is a security zone on the mobile device's main processor. The Huawei Mate9 and Mate9Pro mobile phone TEE modules have a UseAfterFree (UAF) security vulnerability. An attacker lures a user to install a malicious mobile application
VAR-201706-0358 CVE-2017-3748 Lenovo VIBE cell phone's nac_server Vulnerability related to authorization, authority, and access control in components CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE-2017-3749 and CVE-2017-3750 to elevate privileges to the root user (commonly known as 'rooting' or "jail breaking" a device). Lenovo VIBE cell phone's nac_server The component contains vulnerabilities related to authorization, permissions, and access control.CVE-2017-3749 and CVE-2017-3750 Information is obtained, information is tampered with, and service operation is disrupted by exploiting it together with vulnerabilities (DoS) There is a possibility of being put into a state. VIBE is the Android smartphone series launched by Lenovo. There is a local elevation of privilege vulnerability in Lenovo's nac_server component, which can be exploited by an attacker to gain access to the root user. Lenovo VIBE Mobile is prone to a local privilege-escalation vulnerability
VAR-201802-0616 CVE-2017-9969 Schneider Electric IGSS Mobile Information Disclosure Vulnerability CVSS V2: 2.1
CVSS V3: 6.7
Severity: MEDIUM
An information disclosure vulnerability exists in Schneider Electric's IGSS Mobile application version 3.01 and prior. Passwords are stored in clear text in the configuration which can result in exposure of sensitive information. Schneider Electric IGSS Mobile is a set of mobile application for managing IGSS (Shared Services Platform) by Schneider Electric of France. An attacker could use this vulnerability to obtain sensitive information
VAR-201709-1078 CVE-2017-9961 Schneider Electric Pro-face GP-Pro EX Arbitrary code execution vulnerability CVSS V2: 4.6
CVSS V3: 7.8
Severity: HIGH
A vulnerability exists in Schneider Electric's Pro-Face GP Pro EX version 4.07.000 that allows an attacker to execute arbitrary code. Malicious code installation requires an access to the computer. By placing a specific DLL/OCX file, an attacker is able to force the process to load arbitrary DLL and execute arbitrary code in the context of the process. Schneider Electric GP Pro EX Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Pro-face GP-Pro EX is the development software for Pro-face GP4000, GP4100, GP4000M, LT4000M, LT3000, EZ Series, SP5000 Smart Portal series products. Schneider Electric Pro-face GP-Pro EX is prone to an arbitrary code-execution vulnerability. Failed exploit attempts will result in a denial of service condition. Pro-face GP-Pro EX 4.07.000 is vulnerable
VAR-201801-1067 CVE-2017-9965 Schneider Electric Pelco VideoXpert Enterprise Path traversal vulnerability CVSS V2: 5.0
CVSS V3: 5.8
Severity: MEDIUM
An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files. Schneider Electric Pelco VideoXpert Enterprise Contains a path traversal vulnerability.Information may be obtained. PelcoVideoXpertEnterprise is an enterprise video management system. Exploiting these issues will allow an attacker to bypass security restrictions, execute arbitrary code and perform unauthorized actions. Information harvested may aid in launching further attacks. VideoXpert is a video management solution designed forscalability, fitting the needs surveillance operations of any size.VideoXpert Ultimate can also aggregate other VideoXpert systems,tying multiple video management systems into a single interface.The application is vulnerable to an elevation of privilegesvulnerability which can be used by a simple user that can changethe executable file with a binary of choice. The vulnerability existdue to the improper permissions, with the 'F' flag (full) for the'Users' group, for several binary files. The service is installedby default to start on system boot with LocalSystem privileges.Attackers can replace the binary with their rootkit, and on rebootthey get SYSTEM privileges.<br/><br/>VideoXpert services also suffer from an unquoted search path issueimpacting the 'VideoXpert Core' and 'VideoXpert Exports' servicesfor Windows deployed as part of the VideoXpert Setup bundle. A successful attempt would require the local user to be able to inserttheir code in the system root path undetected by the OS or other securityapplications where it could potentially be executed during applicationstartup or reboot. If successful, the local user’s code would executewith the elevated privileges of the application.Tested on: Microsoft Windows 7 Professional SP1 (EN)
VAR-201801-1068 CVE-2017-9966 Schneider Electric Pelco VideoXpert Enterprise Access control vulnerability CVSS V2: 7.1
CVSS V3: 7.1
Severity: HIGH
A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level. Schneider Electric Pelco VideoXpert Enterprise Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. PelcoVideoXpertEnterprise is an enterprise video management system. Schneider Electric Pelco VideoXpert Enterprise is prone to multiple directory traversal and an access-bypass vulnerabilities. Exploiting these issues will allow an attacker to bypass security restrictions, execute arbitrary code and perform unauthorized actions. Information harvested may aid in launching further attacks. VideoXpert is a video management solution designed forscalability, fitting the needs surveillance operations of any size.VideoXpert Ultimate can also aggregate other VideoXpert systems,tying multiple video management systems into a single interface.The application is vulnerable to an elevation of privilegesvulnerability which can be used by a simple user that can changethe executable file with a binary of choice. The vulnerability existdue to the improper permissions, with the 'F' flag (full) for the'Users' group, for several binary files. The service is installedby default to start on system boot with LocalSystem privileges.Attackers can replace the binary with their rootkit, and on rebootthey get SYSTEM privileges.<br/><br/>VideoXpert services also suffer from an unquoted search path issueimpacting the 'VideoXpert Core' and 'VideoXpert Exports' servicesfor Windows deployed as part of the VideoXpert Setup bundle. A successful attempt would require the local user to be able to inserttheir code in the system root path undetected by the OS or other securityapplications where it could potentially be executed during applicationstartup or reboot. If successful, the local user’s code would executewith the elevated privileges of the application.Tested on: Microsoft Windows 7 Professional SP1 (EN)
VAR-201801-1066 CVE-2017-9964 Schneider Electric Pelco VideoXpert Enterprise Path traversal vulnerability CVSS V2: 5.8
CVSS V3: 6.9
Severity: MEDIUM
A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack. VideoXpert is a video management solution designed for scalability, suitable for any size monitoring operation. Attackers can use the vulnerabilities to obtain sensitive information. PelcoVideoXpertEnterprise is an enterprise video management system. SchneiderElectricPelcoVideoXpertEnterprise has a directory traversal vulnerability. Information harvested may aid in launching further attacks. Versions prior to Pelco VideoXpert Enterprise 2.1 are vulnerable. The vulnerability existdue to the improper permissions, with the 'F' flag (full) for the'Users' group, for several binary files. The service is installedby default to start on system boot with LocalSystem privileges.Attackers can replace the binary with their rootkit, and on rebootthey get SYSTEM privileges.<br/><br/>VideoXpert services also suffer from an unquoted search path issueimpacting the 'VideoXpert Core' and 'VideoXpert Exports' servicesfor Windows deployed as part of the VideoXpert Setup bundle. A successful attempt would require the local user to be able to inserttheir code in the system root path undetected by the OS or other securityapplications where it could potentially be executed during applicationstartup or reboot. If successful, the local user’s code would executewith the elevated privileges of the application.Tested on: Microsoft Windows 7 Professional SP1 (EN)
VAR-201802-0615 CVE-2017-9968 Schneider Electric IGSS Mobile Application validation vulnerability CVSS V2: 4.3
CVSS V3: 5.9
Severity: MEDIUM
A security misconfiguration vulnerability exists in Schneider Electric's IGSS Mobile application versions 3.01 and prior in which a lack of certificate pinning during the TLS/SSL connection establishing process can result in a man-in-the-middle attack. Schneider Electric IGSS Mobile The application contains a certificate validation vulnerability.Information may be obtained. An attacker could use this vulnerability to perform a man-in-the-middle attack. An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. This may lead to further attacks. The following products are affected: IGSS Mobile for Android, version 3.01 and prior. IGSS Mobile for iOS, version 3.01 and prior
VAR-201706-1139 No CVE ZTE ZXSS10 Two Voice Gateway Integrated Access Devices Have SNMP String Bypass Vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
ZXSS10 I524-FXS2400A and ZXSS10 I508-FXS0800B are two integrated voice gateway access devices of ZTE Corporation. ZTE ZXSS10 integrated voice gateway access device has SNMP string bypass vulnerability. Attackers can use arbitrary strings or integer values to bypass SNMP access control and write arbitrary strings in the MIB (Management Information Base) to obtain sensitive information about the device.
VAR-201706-1117 No CVE Lenovo Network Royal Smart-V Firewall Has SNMP Protocol Community String Authentication Permission Bypass Vulnerability CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
Smart-V firewall is a security device that integrates ADSL dial-up, routing, firewall, VPN, switch and other functions. The Lenovo NET Smart-V firewall has an SNMP protocol community string authentication permission bypass vulnerability that allows an attacker to use arbitrary strings or integer values to bypass SNMP access control and write arbitrary strings in the MIB To get device sensitive information.
VAR-201709-1079 CVE-2017-9962 Schneider Electric ClearSCADA Memory allocation vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affected include ViewX and the Server Icon. Schneider Electric ClearSCADA Contains a buffer error vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Schneider Electric ClearSCADA is an open software platform that enables remote management of critical architectures. Schneider Electric ClearSCADA has a memory allocation vulnerability that allows an attacker to exploit a vulnerability to submit a special request for a denial of service attack. It is also an important part of telemetry and remote SCADA system solutions. Manage critical infrastructure remotely. A security vulnerability exists in versions of Schneider Electric ClearSCADA prior to August 2017. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements
VAR-201802-0614 CVE-2017-9967 Schneider Electric IGSS SCADA Software Native code execution vulnerability CVSS V2: 4.6
CVSS V3: 7.8
Severity: HIGH
A security misconfiguration vulnerability exists in Schneider Electric's IGSS SCADA Software versions 12 and prior. Security configuration settings such as Address Space Layout Randomization (ASLR) and Data Execution prevention (DEP) were not properly configured resulting in weak security. Schneider Electric IGSS SCADA Software Contains a vulnerability related to configuration settings.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric IGSS SCADA Software is a shared service platform for SCADA (Data Acquisition and Surveillance Control) systems from Schneider Electric, France. A local attacker can exploit the vulnerability to execute arbitrary code in the context of the affected application. Failed attempts may lead to denial-of-service conditions
VAR-201802-0613 CVE-2017-9963 Schneider Electric PowerSCADA Anywhere and Citect Anywhere Cross-Site Request Forgery Vulnerability CVSS V2: 5.8
CVSS V3: 8.1
Severity: HIGH
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social engineering in order to get a legitimate user to click on or access a malicious link/site containing the CSRF attack. PowerSCADA Anywhere Contains a cross-site request forgery vulnerability.Information may be obtained and information may be altered. Schneider Electric PowerSCADA Anywhere and Citect Anywhere are products of Schneider Electric, France. Schneider Electric PowerSCADA Anywhere is a substation monitoring system. PowerSCADA Expert is one of the data acquisition software. Citect Anywhere is a mobile application for PowerSCADA Anywhere. A remote attacker could exploit this vulnerability to perform unauthorized operations
VAR-201802-0617 CVE-2017-9970 Schneider Electric StruxureOn Gateway Remote code execution vulnerability CVSS V2: 9.0
CVSS V3: 7.2
Severity: HIGH
A remote code execution vulnerability exists in Schneider Electric's StruxureOn Gateway versions 1.1.3 and prior. Uploading a zip which contains carefully crafted metadata allows for the file to be uploaded to any directory on the host machine information which could lead to remote code execution. Schneider Electric StruxureOn Gateway Contains a vulnerability related to unlimited uploads of dangerous types of files.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Schneider Electric StruxureOn Gateway is a security gateway software from Schneider Electric, France. The software manages network devices and provides monitoring and alerting services through the data center. An attacker may leverage these issues to upload arbitrary files to the affected computer; this can result in arbitrary code execution within the context of the vulnerable application
VAR-201706-0002 CVE-2012-5010 Cisco Adaptive Security Appliance Vulnerabilities related to security functions in software CVSS V2: 4.8
CVSS V3: 8.1
Severity: HIGH
ASA 5515-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim, ASA 5510 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 8.4.x before 8.4.7 Interim, 8.2.x before 8.2.5 Interim, 9.1.x before 9.1.6 Interim, ASA 5555-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5512-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5520 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 8.2.x before 8.2.5 Interim, 8.4.x before 8.4.7 Interim, 9.1.x before 9.1.6 Interim, ASA 5505 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.2.x before 9.2.4 Interim, 8.4.x before 8.4.7 Interim, 9.1.x before 9.1.6 Interim, ASA 5525-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5512-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim or 9.2.4.SMP, 9.1.x before 9.1.6 Interim, ASA 5545-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5585-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5540 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 8.2.x before 8.2.5 Interim, 8.4.x before 8.4.7 Interim, 9.1.x before 9.1.6 Interim, ASA 5515-X Adaptive Security Appliance ASA for Application Centric Infrastructure (ACI) Device Package 1.2.4.x before 1.2.4.8, ASA 5555-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.2.x before 9.2.4 Interim or 9.2.4.SMP, 9.4.x before 9.4.1 Interim, 9.1.x before 9.1.6 Interim, ASA 5580 Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.1.x before 9.1.6 Interim, ASA 5585-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.2.x before 9.2.4 Interim, 9.4.x before 9.4.1 Interim, ASA 5525-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim or 9.2.4.SMP, 9.1.x before 9.1.6 Interim, ASA 5545-X Adaptive Security Appliance Adaptive Security Appliance (ASA) Software 9.4.x before 9.4.1 Interim, 9.2.x before 9.2.4 Interim or 9.2.4.SMP. 9.1.x before 9.1.6 ASA does not check the source of the ARP request or GARP packets for addresses it performs NAT translation for under unspecified conditions. Cisco ASA is prone to a remote security-bypass vulnerability. Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions. Security vulnerabilities exist in several Cisco products
VAR-201707-0326 CVE-2017-2234 Non-documented developer's screen in Toshiba Lighting & Technology Corporation Home gateway CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges. Yutaka Kokubu of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.The device is operated with the administrative privilege. There is a security hole in TOSHIBAHomeGatewayHEM-GW26A using HEM-GW26A-FW-V1.2.0 and previous firmware and TOSHIBAHomeGatewayHEM-GW16A using HEM-GW16A-FW-V1.2.0 and previous firmware. An attacker could exploit the vulnerability to perform operations with administrator privileges