VARIoT IoT vulnerabilities database
| VAR-201707-1020 | CVE-2017-9494 | Motorola MX011ANM Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet. Motorola MX011ANM Contains vulnerabilities related to authorization, permissions, and access control.Information may be tampered with. MotorolaMX011ANM is a network set-top box device from Motorola, USA. Comcast is a firmware developed by Comcast, Inc., which runs on devices such as gateways and modems. A security vulnerability exists in the Comcast firmware in the MotorolaMX011ANM using the firmware version MX011AN_2.9p6s1_PROD_sey. A remote attacker could exploit this vulnerability to open the RemoteWebInspector
| VAR-201707-1021 | CVE-2017-9495 | Motorola MX011ANM Vulnerable to information disclosure |
CVSS V2: 2.1 CVSS V3: 4.6 Severity: MEDIUM |
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web Inspector script. Motorola MX011ANM Contains an information disclosure vulnerability.Information may be obtained. MotorolaMX011ANM is a network set-top box device from Motorola, USA. Comcast is a firmware developed by Comcast, Inc., which runs on devices such as gateways and modems. A security vulnerability exists in the Comcast firmware in the MotorolaMX011ANM using the firmware version MX011AN_2.9p6s1_PROD_sey. An attacker with a physical location nearby can exploit the vulnerability to read arbitrary files
| VAR-201707-1022 | CVE-2017-9496 | Motorola MX011ANM Access control vulnerability |
CVSS V2: 4.6 CVSS V3: 6.8 Severity: MEDIUM |
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to access an SNMP server by connecting a cable to the Ethernet port, and then establishing communication with the device's link-local IPv6 address. Motorola MX011ANM Contains an access control vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MotorolaMX011ANM is a network set-top box device from Motorola, USA. Comcast is a firmware developed by Comcast, Inc., which runs on devices such as gateways and modems. A security vulnerability exists in the Comcast firmware in the MotorolaMX011ANM using the firmware version MX011AN_2.9p6s1_PROD_sey. An attacker with a physical location is available to access the SNMP server
| VAR-201707-1023 | CVE-2017-9497 | Motorola MX011ANM Input validation vulnerability |
CVSS V2: 7.2 CVSS V3: 6.8 Severity: MEDIUM |
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route. Motorola MX011ANM Contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MotorolaMX011ANM is a network set-top box device from Motorola, USA. Comcast is a firmware developed by Comcast, Inc., which runs on devices such as gateways and modems. A security vulnerability exists in the Comcast firmware in the MotorolaMX011ANM using the firmware version MX011AN_2.9p6s1_PROD_sey. An attacker with a physical location nearby can exploit the vulnerability to execute arbitrary code with root privileges
| VAR-201707-1024 | CVE-2017-9498 | Motorola MX011ANM and Xfinity XR11-20 Voice Remote Vulnerabilities related to authorization, authority, and access control in devices |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware. Motorola MX011ANM and Xfinity XR11-20 Voice Remote Devices have vulnerabilities related to authorization, permissions, and access control.Information may be tampered with. MotorolaMX011ANM is a network set-top box device from Motorola, USA. The XfinityXR11-20VoiceRemote is a voice remote control device. Comcast is a firmware developed by Comcast, Inc., which runs on devices such as gateways and modems. A security vulnerability exists in the Comcast firmware in the MotorolaMX011ANM and XfinityXR11-20VoiceRemote devices using MX011AN_2.9p6s1_PROD_sey firmware, which is due to a lack of protection for the program
| VAR-201706-1122 | No CVE | HP ERK-321A Wireless Mouse Spoofing Vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The HPERK-321A is a wireless desktop device consisting of a mouse and a keyboard. HPERK-321AWirelessMouse has a spoofing vulnerability. Due to unencrypted and unauthenticated mouse data communication, an attacker can exploit the vulnerability to initiate a mouse spoofing attack.
| VAR-201707-1047 | CVE-2017-9482 | Cisco DPC3939 Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by enabling a TELNET daemon (through CVE-2017-9479 exploitation) and then establishing a TELNET session. Cisco DPC3939 Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Cisco DPC3939 is a wireless voice gateway product from Cisco. A security vulnerability exists in the Cisco DPC3939 firmware. Allows an attacker to obtain the root shell of the gateway's network processor (Atom) Linux instance. Comcast is a set of firmware developed by Comcast Corporation of the United States that runs in devices such as gateways and modems
| VAR-201707-1048 | CVE-2017-9483 | Cisco DPC3939 Vulnerabilities related to authorization, permissions, and access control |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users to obtain root access to the Application Processor (AP) Linux system via shell metacharacters in commands. Cisco DPC3939 Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The Cisco DPC3939 is a wireless voice gateway product from Cisco. A security vulnerability exists in the Cisco DPC3939 firmware. Allows an attacker to execute arbitrary commands on an Application Processor (ARM) Linux instance on the gateway. Comcast is a set of firmware developed by Comcast Corporation of the United States that runs in devices such as gateways and modems. An attacker could exploit this vulnerability to gain root access by using shell metacharacters in commands
| VAR-201707-1010 | CVE-2017-9484 | Cisco DPC3939 Vulnerable to information disclosure |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover a CM MAC address by sniffing Wi-Fi traffic and performing simple arithmetic calculations. Cisco DPC3939 Contains an information disclosure vulnerability.Information may be obtained. The Cisco DPC3939 is a wireless voice gateway product from Cisco. A security vulnerability exists in the Cisco DPC3939 firmware. The attacker accesses the CMMAC of the Comcast Customer Gateway by sniffing the Wi-Fi traffic on the gateway. Comcast is a set of firmware developed by Comcast Corporation of the United States that runs in devices such as gateways and modems
| VAR-201707-1011 | CVE-2017-9485 | Cisco DPC3939 Access control vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to write arbitrary data to a known /var/tmp/sess_* pathname by leveraging the device's operation in UI dev mode. Cisco DPC3939 Contains an access control vulnerability.Information may be tampered with. The Cisco DPC3939 is a wireless voice gateway product from Cisco. A security vulnerability exists in the Cisco DPC3939 firmware. Comcast is a set of firmware developed by Comcast Corporation of the United States that runs in devices such as gateways and modems
| VAR-201706-0194 | CVE-2015-2255 | Huawei AR1220 Service disruption in router firmware (DoS) Vulnerabilities |
CVSS V2: 4.3 CVSS V3: 5.9 Severity: MEDIUM |
Huawei AR1220 routers with software before V200R005SPH006 allow remote attackers to cause a denial of service (board reset) via vectors involving a large amount of traffic from the GE port to the FE port. Huawei AR1220 is an enterprise-class modular router from China's Huawei company. There is a security hole in HuaweiAR1220. This vulnerability is used to cause an abnormal reset of the interface board. The following versions are affected: Huawei AR1220 V200R005C00SPC200, V200R005C10SPC500, V200R005C20SPC100, and V200R005C20SPC200
| VAR-201706-0237 | CVE-2015-3913 | plural Huawei Campus Series switch model IP Service operation disruption in the stack (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message. HuaweiS2300 is a switch device of Huawei (Huawei). IPstack is one of the transport protocols. IPstack in several Huawei products has a security vulnerability. The vulnerability stems from the failure of the packet processing module to correctly determine the length of the IP option. An attacker can use this vulnerability to create a board reset by using a special ICMP packet. The following versions are affected: Huawei S2300/S2700/S3300/S3700 V100R00600 Version, V100R006C03 Version, V100R006C05 Version; S5300EI/S5700EI/S5300SI/S5700SI V100R006C00 Version, V200R001C00SPC300 Version, V200R002C00SPC300 Version, V200R003C00SPC300 Version, V200R005C00SPC300 Version; S5300HI/S5700HI S6300EI/S6700EI /S5710HI V200R001C00SPC300 Version, V200R002C00SPC300 Version, V200R003C00SPC300 Version, V200R005C00SPC300 Version; S5300LI/S5700LI/S2350EI/S2750EI V200R001C00SPC300 Version, V200R002C00SPC300 Version, V200R003C00SPC300 Version, V200R005C00SPC300 Version, V200R006C00SPC500 Version, V200R007C00SPC500 Version; S5720HI V200R006C00SPC500 Version, V200R007C00SPC500 Version; S7700/S9300/ S9700 V200R001C00SPC300, V200R002C00SPC300, V200R003C00SPC500, V200R005C00SPC300, V200R006C00SPC500, V200R007C00SPC500; S12700
| VAR-201706-0204 | CVE-2014-6031 | plural F5 Product buffer overflow vulnerability |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
Buffer overflow in the mcpq daemon in F5 BIG-IP systems 10.x before 10.2.4 HF12, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x before 11.4.1 HF9, 11.5.x before 11.5.2 HF1, and 11.6.0 before HF4, and Enterprise Manager 2.1.0 through 2.3.0 and 3.x before 3.1.1 HF5 allows remote authenticated administrators to cause a denial of service via unspecified vectors. plural F5 The product contains a buffer overflow vulnerability.Service disruption by remotely authenticated administrator (DoS) There is a possibility of being put into a state. F5 BIG-IP LTM, etc. are all products of F5 Company in the United States. LTM is a local traffic manager; APM is a solution that provides secure unified access to business-critical applications and networks. Several F5 products have buffer overflow vulnerabilities. A remote attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: BIG-IP LTM Version 11.6.0, Version 11.0.0 through Version 11.5.2, Version 10.0.0 through Version 10.2.4; BIG-IP AAM Version 11.6.0, Version 11.4.0 through Version 11.5.2; BIG-IP AFM Version 11.6.0, Version 11.3.0 through Version 11.5.2; BIG-IP Analytics Version 11.6.0, Version 11.0.0 through Version 11.5.2; BIG-IP APM Version 11.6.0 Versions, 11.0.0 to 11.5.2, 10.1.0 to 10.2.4; BIG-IP ASM 11.6.0, 11.0.0 to 11.5.2, 10.0.0 to 10.2.4 ; BIG-IP Edge Gateway Version 11.0.0 through 11.3.0, Version 10.1.0 through Version 10.2.4; BIG-IP GTM Version 11.6.0, Version 11.0.0 through Version 11.5.2, Version 10.0.0 through Version 10.2.4; BIG-IP Link Controller Version 11.6.0, Version 11.0.0 to Version 11.5.2, Version 10.0.0 to Version 10.2.4; BIG-IP PEM Version 11.6.0, Version 11.3.0 to Version 11.5 .2 versions; BIG-IP PSM versions 11.0.0 through 11.4.1, 10.0.0 through 10.2.4; BIG-IP WebAccelerator versions 11.0.0 through 11.3.0, 10.0.0 through 10.2.4 Versions; BIG-IP WOM 11.0.0 to 11.3.0, 10.0.0 to 10.2.4; Enterprise Manager 3.0.0 to 3.1.1 HF4, 2.1.0 to 2.3.0
| VAR-201706-0191 | CVE-2015-2251 | Huawei OceanStor UDS DeviceManager Information Disclosure Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript. HuaweiOceanStorUDS is a high-density storage node and distributed storage system based on ARM architecture from Huawei. DeviceManager is one of the device management tools. A security vulnerability exists in DeviceManager in Huawei OceanStorUDSV100R002C01SPC101 and previous versions
| VAR-201706-0192 | CVE-2015-2252 | Huawei OceanStor UDS Code Injection Vulnerability |
CVSS V2: 9.3 CVSS V3: 8.8 Severity: HIGH |
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts. HuaweiOceanStorUDS is a high-density storage node and distributed storage system based on ARM architecture from Huawei. A security vulnerability exists in HuaweiOceanStorUDSV100R002C01SPC101 and earlier versions
| VAR-201706-0193 | CVE-2015-2253 | Huawei OceanStor UDS Information Disclosure Vulnerability |
CVSS V2: 3.5 CVSS V3: 5.0 Severity: MEDIUM |
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document. HuaweiOceanStorUDS is a high-density storage node and distributed storage system based on ARM architecture from Huawei. A security vulnerability exists in the XML interface in HuaweiOceanStorUDSV100R002C01SPC101 and earlier versions
| VAR-201906-0838 | CVE-2017-9382 | Vera VeraEdge and Veralite Path traversal vulnerability in devices |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides UPnP services that are available on port 3480 and can also be accessed via port 80 using the url "/port_3480". It seems that the UPnP services provide "file" as one of the service actions for a normal user to read a file that is stored under the /etc/cmh-lu folder. It retrieves the value from the "parameters" query string variable and then passes it to an internal function "FileUtils::ReadFileIntoBuffer" which is a library function that does not perform any sanitization on the value submitted and this allows an attacker to use directory traversal characters "../" and read files from other folders within the device. Vera VeraEdge and Veralite The device contains a path traversal vulnerability.Information may be obtained. FileUtils is an open source file management tool. A security vulnerability exists in Vera VeraEdge version 1.7.19 and Veralite version 1.7.481. The vulnerability is caused by the program not filtering the value submitted by the user. An attacker can use the directory traversal character '../' to exploit this vulnerability to read the contents of other files
| VAR-201906-0837 | CVE-2017-9381 | Vera VeraEdge and Veralite Device cross-site request forgery vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a user with the capability of installing or deleting apps on the device using the web management interface. It seems that the device does not implement any cross-site request forgery protection mechanism which allows an attacker to trick a user who navigates to an attacker controlled page to install or delete an application on the device. Note: The cross-site request forgery is a systemic issue across all other functionalities of the device. Vera VeraEdge and Veralite The device contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. The vulnerability stems from the WEB application not adequately verifying that the request is from a trusted user. An attacker could exploit this vulnerability to send unexpected requests to the server through an affected client
| VAR-201706-1127 | No CVE | Hikvision remote monitoring client system treeformap.php file id parameter has SQL injection vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Hikvision is a video-centric IoT solution and data operation service provider.
Hikvision remote monitoring client system treeformap.php file id parameter has a SQL injection vulnerability. Allows attackers to exploit vulnerabilities to obtain database sensitive information.
| VAR-201706-0660 | CVE-2017-7910 | Digital Canal Structural Wind Analysis Buffer error vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-of-service attack.
Attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed