VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201705-4199 No CVE Remote Command Execution Vulnerability in MyFAX Network Fax Server CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
myFAX fax server, also known as myfax electronic fax machine, is an intelligent high-tech product that combines fax technology with network technology. A remote command execution vulnerability exists in the MyFAX network fax server, allowing remote attackers to execute arbitrary commands through unspecified vectors.
VAR-201711-1053 CVE-2017-8700 ASP.NET Core In Cross-Origin Resource Sharing Vulnerability that can be bypassed CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". An attacker can use this vulnerability to obtain sensitive information about the target system by submitting malicious input to the affected software. Microsoft ASP.NET Core is a cross-platform open source framework of Microsoft Corporation of the United States. The framework is used to build cloud-based applications such as web applications, IoT applications, and mobile backends. ASP.NET Core 1.0, and 1.1 are vulnerable
VAR-201706-0556 CVE-2017-6674 Cisco FirePOWER System software feature-license Set on the device in the management function URL Vulnerabilities that bypass the filter CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass URL filters that have been configured for an affected device. More Information: CSCvb16413. Known Affected Releases: 6.0.1 6.1.0 6.2.0 6.2.1. Known Fixed Releases: 6.2.1 6.2.0.1 6.1.0.2. An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks. This issue is tracked by Cisco Bug ID CSCvb16413. The vulnerability stems from the fact that URL filtering licenses can be disabled
VAR-201711-0226 CVE-2017-2710 Beethoven-W09A and CRR-L09 Vulnerabilities related to authorization, permissions, and access control CVSS V2: 2.1
CVSS V3: 4.6
Severity: MEDIUM
BTV-W09C229B002CUSTC229D005,BTV-W09C233B029, earlier than BTV-W09C100B006CUSTC100D002 versions, earlier than BTV-W09C128B003CUSTC128D002 versions, earlier than BTV-W09C199B002CUSTC199D002 versions, earlier than BTV-W09C209B005CUSTC209D001 versions, earlier than BTV-W09C331B002CUSTC331D001 versions, earlier than CRR-L09C432B390 versions, earlier than CRR-L09C605B355CUSTC605D003 versions have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker can perform some operations to update the Google account. As a result, the FRP function is bypassed. Beethoven-W09A and CRR-L09 Contains vulnerabilities related to authorization, permissions, and access control.Information may be tampered with. HuaweiBeethoven-W09A and Huawei CRR-L09 are both Huawei's smartphones. There are security bypass vulnerabilities in the HuaweiBeethoven-W09A and CRR-L09 phones. Huawei Smart Phones are prone to a local security-bypass vulnerability. Attackers can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks. The Huawei Beethoven-W09A and Huawei CRR-L09 are both smartphones from the Chinese company Huawei
VAR-201705-3873 CVE-2017-9214 Open vSwitch Vulnerable to integer underflow CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`. Open vSwitch (OvS) Contains an integer underflow vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. Open vSwitch is prone to a remote integer-underflow vulnerability because they fail to sufficiently validate an integer value. Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploits may result in denial-of-service conditions. Open vSwitch 2.7.0 is vulnerable; other versions may also be affected. Open vSwitch (OVS) is a multi-layer virtual switch product based on open source technology (following the Apache2.0 license). It supports large-scale network automation, standard management interfaces and protocols, etc. through programming extensions. There is an integer overflow vulnerability in the 'ofputil_pull_queue_get_config_reply10' function of lib/ofp-util.c file in OvS 2.7.0 version. ========================================================================== Ubuntu Security Notice USN-3450-1 October 11, 2017 openvswitch vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Open vSwitch. Software Description: - openvswitch: Ethernet virtual switch Details: Bhargava Shastry discovered that Open vSwitch incorrectly handled certain OFP messages. (CVE-2017-9214) It was discovered that Open vSwitch incorrectly handled certain OpenFlow role messages. (CVE-2017-9263) It was discovered that Open vSwitch incorrectly handled certain malformed packets. This issue only affected Ubuntu 17.04. (CVE-2017-9265) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: openvswitch-common 2.6.1-0ubuntu5.1 Ubuntu 16.04 LTS: openvswitch-common 2.5.2-0ubuntu0.16.04.2 In general, a standard system update will make all the necessary changes. 1473735 - ovs-vswitchd crashes with SIGSEGV randomly when adding/removing interfaces 6. X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.25]); Thu, 03 Aug 2017 12:39:24 +0000 (UTC) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: openvswitch security, bug fix, and enhancement update Advisory ID: RHSA-2017:2418-01 Product: Fast Datapath Advisory URL: https://access.redhat.com/errata/RHSA-2017:2418 Issue date: 2017-08-03 CVE Names: CVE-2017-9214 CVE-2017-9263 CVE-2017-9264 CVE-2017-9265 ===================================================================== 1. Summary: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Channel to provide early releases to layered products - noarch, x86_64 3. Description: Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. The following packages have been upgraded to a later upstream version: openvswitch (2.7.2). An attacker could use this flaw to cause a remote DoS. (CVE-2017-9214) * In Open vSwitch (OvS), while parsing an OpenFlow role status message there is a call to the abort() function for undefined role status reasons in the function `ofp_print_role_status_message` in `lib/ofp-print.c` that may be leveraged toward a remote DoS attack by a malicious switch. (CVE-2017-9263) * A buffer over-read was found in the Open vSwitch (OvS) firewall implementation. This flaw can be triggered by parsing a specially crafted TCP, UDP, or IPv6 packet. A remote attack could use this flaw to cause a Denial of Service (DoS). An attacker could use this flaw to cause a Denial of Service (DoS). (CVE-2017-9265) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Package List: Channel to provide early releases to layered products: Source: openvswitch-2.7.2-1.git20170719.el7fdp.src.rpm noarch: openvswitch-test-2.7.2-1.git20170719.el7fdp.noarch.rpm python-openvswitch-2.7.2-1.git20170719.el7fdp.noarch.rpm x86_64: openvswitch-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-debuginfo-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-devel-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-ovn-central-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-ovn-common-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-ovn-docker-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-ovn-host-2.7.2-1.git20170719.el7fdp.x86_64.rpm openvswitch-ovn-vtep-2.7.2-1.git20170719.el7fdp.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-9214 https://access.redhat.com/security/cve/CVE-2017-9263 https://access.redhat.com/security/cve/CVE-2017-9264 https://access.redhat.com/security/cve/CVE-2017-9265 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFZgxmYXlSAg2UNWIIRAuzuAJ9Dngapo5j66itwFnpsvl92GKMAywCfb2Ah V7og7GgSn4a1oFzQjIZHeXk= =qOi+ -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce
VAR-201705-4193 No CVE D-Link DAP-1360 Cross-Site Request Forgery Vulnerability (CNVD-2017-07250) CVSS V2: 7.5
CVSS V3: -
Severity: HIGH
The D-Link DAP-1360 is a router. D-LinkDAP-1360 has a cross-site request forgery vulnerability that can be exploited by remote attackers to perform elevated CSRF attacks by using domain names.
VAR-201802-0734 CVE-2017-8953 HPE LoadRunner and Performance Center Vulnerable to cross-site scripting

Related entries in the VARIoT exploits database: VAR-E-201707-0383
CVSS V2: 3.5
CVSS V3: 5.4
Severity: MEDIUM
A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content on behalf of the victim on the SharePoint site
VAR-201706-0658 CVE-2017-7903 Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Vulnerability related to cryptographic strength in the controller CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected products use a numeric password with a small maximum character size for the password. Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 The controller contains a cryptographic strength vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-Bradley MicroLogix 1100 1763-L16AWA Series A is a programmable logic controller (PLC) product from Rockwell Automation. Security vulnerabilities exist in several Rockwell Automation products. An attacker could exploit the vulnerability to gain unauthorized access to the affected device. Attackers may exploit these issues to bypass authentication mechanism, bypass security restrictions and perform unauthorized actions, gain sensitive information and cause denial-of-service conditions
VAR-201706-0657 CVE-2017-7902 Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Cryptographic vulnerability in the controller CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. The affected product reuses nonces, which may allow an attacker to capture and replay a valid request until the nonce is changed. Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 The controller contains a cryptographic vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-Bradley MicroLogix 1100 1763-L16AWA Series A is a programmable logic controller (PLC) product from Rockwell Automation. Security vulnerabilities exist in several Rockwell Automation products. An attacker could exploit this vulnerability to capture and respond to valid requests. Attackers may exploit these issues to bypass authentication mechanism, bypass security restrictions and perform unauthorized actions, gain sensitive information and cause denial-of-service conditions
VAR-201706-0656 CVE-2017-7901 plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Vulnerability related to insufficient random value in controller CVSS V2: 9.0
CVSS V3: 8.6
Severity: HIGH
A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. Insufficiently random TCP initial sequence numbers are generated, which may allow an attacker to predict the numbers from previous values. This may allow an attacker to spoof or disrupt TCP connections, resulting in a denial of service for the target device. plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 The controller contains a vulnerability related to the use of insufficient random values.By the attacker, TCP Impaired service operation by spoofing or interrupting connection (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-Bradley MicroLogix 1100 1763-L16AWA Series A is a programmable logic controller (PLC) product from Rockwell Automation. An attacker could exploit the vulnerability to cause a denial of service. Attackers may exploit these issues to bypass authentication mechanism, bypass security restrictions and perform unauthorized actions, gain sensitive information and cause denial-of-service conditions
VAR-201706-0655 CVE-2017-7899 plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Vulnerabilities related to certificate and password management in the controller CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. User credentials are sent to the web server using the HTTP GET method, which may result in the credentials being logged. This could make user credentials available for unauthorized retrieval. plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 The controller contains a vulnerability related to certificate / password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-Bradley MicroLogix 1100 1763-L16AWA Series A is a programmable logic controller (PLC) product from Rockwell Automation. An information disclosure vulnerability exists in several Rockwell Automation products. An attacker could use this vulnerability to recover a user certificate. Attackers may exploit these issues to bypass authentication mechanism, bypass security restrictions and perform unauthorized actions, gain sensitive information and cause denial-of-service conditions
VAR-201706-0833 CVE-2017-9097 plural NetBiter Used in products Antiweb Path traversal vulnerability CVSS V2: 6.4
CVSS V3: 9.1
Severity: CRITICAL
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file. plural NetBiter Used in products Antiweb Contains a path traversal vulnerability.Information may be obtained and information may be altered
VAR-201705-3759 CVE-2017-7913 plural Moxa OnCell Vulnerabilities related to certificate and password management in products CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application's configuration file contains parameters that represent passwords in plaintext. plural Moxa OnCell The product contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MoxaOnCellG3110-HSPA is a product of China's Moxa Corporation. The OnCellG3110-HSPA is an industrial-grade IP gateway. The OnCell5104-HSPA is an industrial-grade cellular router. A plaintext password vulnerability exists in several Moxa products. An attacker could exploit this vulnerability to obtain sensitive information. Attackers may exploit these issues to bypass authentication mechanism and gain unauthorized access, to gain sensitive information and perform certain unauthorized actions in the context of the affected application. Other attacks are also possible
VAR-201705-3760 CVE-2017-7915 plural Moxa OnCell Vulnerabilities related to security functions in products CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. An attacker can freely use brute force to determine parameters needed to bypass authentication. plural Moxa OnCell The product contains vulnerabilities related to security functions.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MoxaOnCellG3110-HSPA is a product of China's Moxa Corporation. The OnCellG3110-HSPA is an industrial-grade IP gateway. The OnCell5104-HSPA is an industrial-grade cellular router. A number of Moxa products have brute force exploits. Attackers may exploit these issues to bypass authentication mechanism and gain unauthorized access, to gain sensitive information and perform certain unauthorized actions in the context of the affected application. Other attacks are also possible. The following products and versions are affected: Mosa OnCell G3110-HSPA 1.3 build 15082117 and earlier; OnCell G3110-HSDPA 1.2 Build 09123015 and earlier; OnCell G3150-HSDPA 1.4 Build 11051315 and earlier; OnCell 5104-HSDPA; OnCell 5104-HSPA; OnCell 5004-HSPA
VAR-201705-3761 CVE-2017-7917 plural Moxa OnCell Product cross-site request forgery vulnerability CVSS V2: 6.8
CVSS V3: 8.8
Severity: HIGH
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device. plural Moxa OnCell The product contains a cross-site request forgery vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. MoxaOnCellG3110-HSPA is a product of China's Moxa Corporation. The OnCellG3110-HSPA is an industrial-grade IP gateway. The OnCell5104-HSPA is an industrial-grade cellular router. A cross-site request forgery vulnerability exists in several Moxa products due to insufficient verification requests from the program. Moxa OnCell series products are prone to multiple security vulnerabilities. Attackers may exploit these issues to bypass authentication mechanism and gain unauthorized access, to gain sensitive information and perform certain unauthorized actions in the context of the affected application. Other attacks are also possible
VAR-201706-0654 CVE-2017-7898 plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 Vulnerabilities related to authorization, authority, and access control in the controller CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16BBB, Series A and B, Version 16.00 and prior versions; 1763-L16BWA, Series A and B, Version 16.00 and prior versions; and 1763-L16DWD, Series A and B, Version 16.00 and prior versions and Allen-Bradley MicroLogix 1400 programmable logic controllers 1766-L32AWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWA, Series A and B, Version 16.00 and prior versions; 1766-L32BWAA, Series A and B, Version 16.00 and prior versions; 1766-L32BXB, Series A and B, Version 16.00 and prior versions; 1766-L32BXBA, Series A and B, Version 16.00 and prior versions; and 1766-L32AWAA, Series A and B, Version 16.00 and prior versions. There are no penalties for repeatedly entering incorrect passwords. plural Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 The controller contains vulnerabilities related to authorization, authority, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Rockwell Automation Allen-Bradley MicroLogix 1100 1763-L16AWA Series A is a programmable logic controller (PLC) product from Rockwell Automation. Security vulnerabilities exist in several Rockwell Automation products. Attackers may exploit these issues to bypass authentication mechanism, bypass security restrictions and perform unauthorized actions, gain sensitive information and cause denial-of-service conditions
VAR-201705-2537 CVE-2015-5401 Teradata Gateway and Teradata Express Service disruption in (DoS) Vulnerabilities CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Teradata Gateway and Teradata Express There is a service disruption ( Database crash ) There are vulnerabilities that are put into a state.A remote attacker could create a malformed CONFIG REQUEST Service disruption via message ( Database crash ) There is a possibility of being put into a state. TeradataGateway and TDExpress are products of Teradata. The former is a gateway product, the latter is a free database software. There are security holes in TeradataGateway and TDExpress. Multiple Teradata Products are prone to a denial-of-service vulnerability. The following products are vulnerable: Teradata Gateway prior to 15.00.03.02-1, 15.10.x prior to 15.10.00.01-1 and Teradata Express prior to 15.00.02.08_Sles10 and 15.00.02.08_Sles11. Both Teradata Gateway and TD Express are products of Teradata Corporation of the United States. Security vulnerabilities exist in Teradata Gateway and TD Express
VAR-201705-4201 No CVE Cache Master Network Device Has SQL Injection Vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Cache Master can optimize caches for web videos (including mobile videos), and also intelligently cache http downloads and web images of web pages. The cache master network device has a SQL injection vulnerability. An attacker can use this vulnerability to log in to the website's background to obtain administrator permissions and database sensitive information.
VAR-201705-3237 CVE-2017-2523 plural Apple Product Foundation Vulnerability in arbitrary code execution in components CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data. Apple iOS, WatchOS, macOS and tvOS are prone to a memory corruption vulnerability. Failed exploit attempts may result in a denial-of-service condition. The following versions fixes the issue: Versions prior to Apple iOS 10.3.2 Versions prior to Apple watchOS 3.2.2 Versions prior to Apple tvOS 10.2.1 Versions prior to Apple macOS 10.12.5. in the United States. Apple iOS is an operating system developed for mobile devices; tvOS is a smart TV operating system. Foundation is a framework that provides basic system services for all applications
VAR-201705-4195 No CVE MasterCard password vulnerability exists in the CITIC Xi'an recruitment system CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
CIIC Xi'an Recruitment System is a resume information storage and entry system. There is a universal password login vulnerability in the CITIC Xi'an recruitment system. The attacker enters the universal password 'or' 1 '=' 1 or 'or' = 'or' to log in to the system and view the user's sensitive information.