VARIoT IoT vulnerabilities database
| VAR-201706-0130 | CVE-2016-3019 | IBM Security Access Manager for Web Vulnerability in deciphering sensitive information |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462. Vendors have confirmed this vulnerability IBM X-Force ID: 114462 It is released as.An attacker could decipher sensitive information.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. The product enables access management control through integrated appliances for web, mobile and cloud computing
| VAR-201706-0125 | CVE-2016-3051 | IBM Security Access Manager for Web Vulnerable to privileged access to the server |
CVSS V2: 4.0 CVSS V3: 4.3 Severity: MEDIUM |
IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.
Attackers can exploit this issue to bypass security restrictions and gain unauthorized access to the vulnerable system; this may aid in launching further attacks. There are security holes in ISAM for Web
| VAR-201711-0977 | CVE-2017-8139 | HedEx Vulnerable to cross-site scripting |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
HedEx Earlier than V200R006C00 versions have the stored cross-site scripting (XSS) vulnerability. Attackers can exploit the vulnerability to plant malicious scripts into the configuration file to interrupt the services of legitimate users. Huawei HedEx Lite is a document management software developed by Huawei in China
| VAR-201711-0976 | CVE-2017-8138 | HedEx Vulnerable to cross-site request forgery |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
HedEx Earlier than V200R006C00 versions has a cross-site request forgery (CSRF) vulnerability. An attacker could trick a user into accessing a website containing malicious scripts which may tamper with configurations and interrupt normal services. HedEx Contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei HedEx Lite is a document management software developed by Huawei in China. Attackers can use malicious scripts to exploit this vulnerability to modify the configuration and interfere with the operation of legitimate users
| VAR-201711-0975 | CVE-2017-8137 | HedEx Vulnerabilities related to untrusted search paths |
CVSS V2: 9.3 CVSS V3: 7.8 Severity: HIGH |
HedEx Earlier than V200R006C00 versions has a dynamic link library (DLL) hijacking vulnerability due to calling the DDL file by accessing a relative path. An attacker could exploit this vulnerability to tamper with the DLL file, leading to DLL hijacking. HedEx Contains an unreliable search path vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei HedEx Lite is a document management software developed by Huawei in China
| VAR-201711-0974 | CVE-2017-8136 | HedEx Vulnerable to information disclosure |
CVSS V2: 4.3 CVSS V3: 5.5 Severity: MEDIUM |
HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability. An attacker could exploit it to download arbitrary files on a target device to cause information leak. HedEx Contains an information disclosure vulnerability.Information may be obtained. Huawei HedEx Lite is a document management software developed by Huawei in China
| VAR-201706-0423 | CVE-2017-2193 | Installer of Tera Term may insecurely load Dynamic Link Libraries |
CVSS V2: 9.3 CVSS V3: 7.8 Severity: HIGH |
Untrusted search path vulnerability in the installer of Tera Term 4.94 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Eili Masami of Tachibana Lab. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.Arbitrary code may be executed with the privilege of the user invoking the installer. TeraTerm is a terminal emulator that supports serial port, telnet and SSH connections. Installer is one of the installers. An attacker could exploit the vulnerability with a malicious DLL in the directory to gain access. Tera Term Installer is prone to a remote code-execution vulnerability.
A remote attacker can leverage this issue to execute arbitrary code in the context of the affected application.
Tera Term Installer 4.94 and prior versions are vulnerable
| VAR-201706-0463 | CVE-2017-6039 | Phoenix Broadband Technologies LLC PowerAgent SC3 Site Controller Security Bypass Vulnerability |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device. PhoenixBroadbandTechnologies LLC PowerAgentSC3 is a monitoring company launched by American company Phoenix Technology Co., Ltd. Phoenix Broadband PowerAgent SC3 BMS is a remote power detection system of Phoenix Broadband Company in the United States
| VAR-201711-0973 | CVE-2017-8135 | FusionSphere OpenStack Software injection command vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. FusionSphere OpenStack The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere OpenStack is prone to multiple command-injection vulnerabilities.
An attacker may exploit these issues to execute arbitrary code within the context of the affected application; this may aid in further attacks. Huawei FusionSphere OpenStack is a set of cloud platform software for FusionSphere (cloud operating system) of Huawei in China in ICT scenarios. There is a command injection vulnerability in Huawei FusionSphere OpenStack V100R006C00 and V100R006C10
| VAR-201711-0972 | CVE-2017-8134 | FusionSphere OpenStack Software injection command vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. FusionSphere OpenStack The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere OpenStack is a set of cloud platform software for FusionSphere (cloud operating system) of Huawei in China in ICT scenarios. There is a command injection vulnerability in Huawei FusionSphere OpenStack V100R006C00 and V100R006C10
| VAR-201711-0971 | CVE-2017-8133 | Huawei iManager NetEco Software injection command vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Huawei iManager NetEco with software V600R008C00 and V600R008C10 has a command injection vulnerability. An authenticated, remote attacker could exploit this vulnerability to send malicious packets to a target device. Successful exploit could enable a low privileged user to execute commands that a high privileged user could execute, causing the files to be tampered with or deleted. Huawei iManager NetEco The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei iManager NetEco is a computer room dynamic environment monitoring system independently developed by Huawei. The vulnerability is caused by the insufficient execution of input validation in the program
| VAR-201711-0970 | CVE-2017-8132 | FusionSphere OpenStack Software injection command vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. FusionSphere OpenStack The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere OpenStack is a set of cloud platform software for FusionSphere (cloud operating system) of Huawei in China in ICT scenarios. There is a command injection vulnerability in Huawei FusionSphere OpenStack V100R006C00 and V100R006C10
| VAR-201711-0969 | CVE-2017-8131 | FusionSphere OpenStack Software injection command vulnerability |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
The FusionSphere OpenStack with software V100R006C00 and V100R006C10 has a command injection vulnerability due to the insufficient input validation on four TCP listening ports. An unauthenticated attacker can exploit the vulnerabilities to gain root privileges by sending some messages with malicious commands. FusionSphere OpenStack The software contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Huawei FusionSphere OpenStack is a set of cloud platform software for FusionSphere (cloud operating system) of Huawei in China in ICT scenarios. There is a command injection vulnerability in Huawei FusionSphere V100R006C00 and V100R006C10
| VAR-201705-3296 | CVE-2017-5688 | Intel Solid State Drive Toolbox Vulnerability in which privileges are elevated |
CVSS V2: 7.2 CVSS V3: 6.7 Severity: MEDIUM |
There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code
| VAR-201711-1047 | CVE-2017-9315 | Dahua IP Camera and IP PTZ Cryptographic vulnerability |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Customer of Dahua IP camera or IP PTZ could submit relevant device information to receive a time limited temporary password from Dahua authorized dealer to reset the admin password. The algorithm used in this mechanism is potentially at risk of being compromised and subsequently utilized by attacker. Dahua IP Camera and IP PTZ Contains a cryptographic vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Dahua Technology IP Camera. Authentication is not required to exploit this vulnerability.The specific flaw exists within the disaster recovery password functionality. If the device uses its default settings, the password generation algorithm produces a predictable result. An attacker can leverage this vulnerability to gain control of the device under attack. Dahua IPC-HFW and others are network camera equipment of Dahua Company of China. There are security vulnerabilities in several Dahua products. An attacker could use this vulnerability to reset the administrator password. Dahua IPC-HFW, etc. The following products are affected: Dahua IPC-HFW1XXX Build 2015/07 to 2017/03; IPC-HDW1XXX Build 2015/07 to 2017/03; IPC-HDBW1XXX Build 2015/07 to 2017/03; IPC- HFW2XXX Build 2015/07 to 2017/03; IPC-HDW2XXX Build 2015/07 to 2017/03; IPC-HDBW2XXX Build 2015/07 to 2017/03; IPC-HFW4XXX Build 2015/07 to 2017 /03 version; IPC-HDW4XXX Build 2015/07 to 2017/03 version; IPC-HDBW4XXX Build 2015/07 to 2017/03 version; IPC-HF5XXX Build 2015/07 to 2017/03 version; IPC-HFW5XXX Build 2015/07 to 2017/03; IPC-HDW5XXX Build 2015/07 to 2017/03; IPC-HDBW5XXX Build 2015/07 to 2017/03; IPC-HF8XXX Build 2015/07 to 2017/03 Version; IPC-HFW8XXX Build 2015/07 to 2017/03; IPC-HDBW8XXX Build 2015/07 to 2017/03; IPC-EBW8XXX Build 2015/07 to 2017/03; IPC-PFW8xxx Build 2015/ 07 version to 2017/03 version; IPC-PDBW8xxx Build 2015/07 version to 2017/03 version; IPC-HUM8xxx Build 2015/07 version to 2017/03 version
| VAR-201806-0800 | CVE-2017-9312 | Allen-Bradley L30ERMS Vulnerability related to input confirmation in safety devices |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Improperly implemented option-field processing in the TCP/IP stack on Allen-Bradley L30ERMS safety devices v30 and earlier causes a denial of service. When a crafted TCP packet is received, the device reboots immediately. Allen-Bradley L30ERMS A safety device contains a vulnerability related to input validation.Service operation interruption (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-BradleyCompactGuardLogix5370controller and others are programmable logic controller products of Rockwell Automation. Input validation vulnerabilities exist in several RockwellAutomation products.
An attacker can exploit this issue to cause denial-of-service condition.
The following products and versions are vulnerable:
Allen-Bradley CompactLogix 5370 L1 30.012 and prior
Allen-Bradley CompactLogix 5370 L2 30.012 and prior
Allen-Bradley CompactLogix 5370 L3 30.012 and prior
Allen-Bradley Armor CompactLogix 5370 L3 30.012 and prior
Allen-Bradley Compact GuardLogix 5370 30.012 and prior
Allen-Bradley Armor Compact GuardLogix 5370 30.012 and prior
| VAR-201711-1046 | CVE-2017-9314 | Dahua NVR Authentication vulnerabilities in model software |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message. Dahua NVR The model software contains authentication vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. DahuaNVR50XX and so on are all Dahua's network hard disk camera products. There are security vulnerabilities in several Dahua products
| VAR-201711-1048 | CVE-2017-9316 | plural Dahua Technology Authentication vulnerabilities in products |
CVSS V2: 5.8 CVSS V3: 6.5 Severity: MEDIUM |
Firmware upgrade authentication bypass vulnerability was found in Dahua IPC-HDW4300S and some IP products. The vulnerability was caused by internal Debug function. This particular function was used for problem analysis and performance tuning during product development phase. It allowed the device to receive only specific data (one direction, no transmit) and therefore it was not involved in any instance of collecting user privacy data or allowing remote code execution. plural Dahua Technology The product contains authentication vulnerabilities.Tampering with information and disrupting service operations (DoS) There is a possibility of being put into a state. DahuaIPC-HDW4300S is the IP camera equipment of Dahua Company of China. The following products are affected: Dahua IPC-HDW4300S; NVR11HS; IPC-HFW4X00; IPC-HDW4X00; IPC-HDBW4X00;
| VAR-201804-1052 | CVE-2017-7002 | Apple iOS and macOS of SQLite Vulnerability in arbitrary code execution in components |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of WebSQL. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Failed exploit attempts will likely cause a denial-of-service condition. Both Apple iOS and macOS Sierra are products of Apple Inc. Apple iOS is an operating system developed for mobile devices; macOS Sierra is a dedicated operating system developed for Mac computers. SQLite is one of the C-language-based open source embedded relational database management components developed by American software developer D.Richard Hipp. A memory corruption vulnerability exists in the SQLite component in Apple iOS versions prior to 10.3.2 and masOS Sierra versions prior to 10.12.5
| VAR-201804-1051 | CVE-2017-7001 | Apple iOS and macOS of SQLite Vulnerability in arbitrary code execution in components |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the handling of WebSQL. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Failed exploits may result in denial-of-service conditions. Both Apple iOS and macOS Sierra are products of Apple Inc. Apple iOS is an operating system developed for mobile devices; macOS Sierra is a dedicated operating system developed for Mac computers. SQLite is one of the C-language-based open source embedded relational database management components developed by American software developer D.Richard Hipp