VARIoT IoT vulnerabilities database
| VAR-201705-3536 | CVE-2017-6079 | Edgewater Networks Edgemarc Command injection vulnerability in the appliance |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006. Edgewater Networks Edgemarc The appliance contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Edgewater Networks Edgemarc is the device of Edgewater Networks. There are arbitrary command injection vulnerabilities in EdgewaterNetworksEdgemarc. An attacker could exploit this vulnerability to inject arbitrary commands into the context of an affected application, causing further attacks. HTTP web-management appliance is one of the HTTP Web management programs. A security vulnerability exists in the HTTP web-management application on Edgewater Networks Edgemarc devices
| VAR-201702-0960 | CVE-2017-6127 |
DigiSol DG-HR1400 Wireless Router Cross-Site Request Forgery Vulnerability
Related entries in the VARIoT exploits database: VAR-E-201702-0538 |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID, (2) change the Wi-Fi password, or (3) possibly have unspecified other impact via crafted requests to form2WlanBasicSetup.cgi. The DigiSolDG-HR1400 WirelessRouter is a wireless broadband home router. A cross-site request forgery vulnerability exists in the accessportal of DigiSolDG-HR1400 WirelessRouter. Allows remote attackers to build malicious URIs, entice users to resolve, and perform malicious actions in the target user context. DIGISOL DG-HR1400 is prone to multiple cross-site request-forgery vulnerabilities. This may lead to further attacks.
DG-HR1400 1.00.02 is vulnerable; other versions may also be affected
| VAR-201704-1571 | CVE-2017-7689 | Schneider Electric homeLYnk Controller Command injection vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0. A remote attacker exploited the vulnerability to obtain sensitive information.
An attacker can exploit this issue to execute arbitrary commands on the affected system with root privileges. This may aid in further attacks
| VAR-201702-0952 | CVE-2017-6077 | NETGEAR DGN2200 Device firmware ping.cgi In any OS Command execution vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request. The NETGEARDGN2200 is an ADSL router device. There are arbitrary command execution vulnerabilities in ping.cgi in the NETGEARDGN220010.0.0.50 version. NETGEAR DGN2200 is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
NETGEAR DGN2200 10.0.0.50 is vulnerable. There is a security vulnerability in the ping.cgi file in NETGEAR DGN2200 with firmware version 10.0.0.50 and earlier
| VAR-201702-0159 | CVE-2016-10227 | Zyxel USG50 Security Appliance and NWA3560-N Access Point Service disruption in (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets. ZyXELUSG50 and others are products of ZyXEL Technology. The ZyXELUSG50 is a firewall product. ZyXELNWA3560-N is a switch product. A remote denial of service vulnerability exists in several Zyxel products. Both Zyxel USG50 Security Appliance and NWA3560-N Access Point are products of Zyxel. The former is a set of network security firewall equipment, and the latter is a wireless access point product. Security vulnerabilities exist in Zyxel USG50 Security Appliance and NWA3560-N Access Point
| VAR-201704-0063 | CVE-2016-10226 | Safari Technology Preview Distributed by WebKit of JavaScriptCore Service disruption in (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (bitfield out-of-bounds read and application crash) via crafted JavaScript code that is mishandled in the operatorString function, related to assembler/MacroAssemblerARM64.h, assembler/MacroAssemblerX86Common.h, and wasm/WasmB3IRGenerator.cpp. Apple Safari Technology Preview is a browser of Apple (Apple). WebKit is an open source web browser engine developed by the KDE community and is currently used by browsers such as Apple Safari and Google Chrome. There is a security vulnerability in the JavaScriptCore of WebKit released in Apple Safari Technology Preview Release 18
| VAR-201702-0388 | CVE-2016-4617 | Apple OS X Vulnerable to sandbox escape |
CVSS V2: 4.6 CVSS V3: 8.8 Severity: HIGH |
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component. Apple macOS is prone to multiple security-bypass vulnerabilities.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks. Apple macOS Sierra is a dedicated operating system developed by Apple for Mac computers. libxpc is an open source implementation of Apple's XPC library. A security vulnerability exists in the libxpc component of Apple macOS Sierra prior to 10.12. An attacker can exploit this vulnerability to break out of the sandbox
| VAR-201702-0266 | CVE-2016-7742 | Apple macOS of xar Vulnerability in arbitrary code execution in components |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote attackers to execute arbitrary code via a crafted archive that triggers use of uninitialized memory locations. Apple macOS is prone to an arbitrary code-execution vulnerability. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to macOS 10.12.2 are vulnerable. Apple macOS Sierra is a dedicated operating system developed by Apple for Mac computers. xar is one of those tools that provides an easily extensible archive format
| VAR-201702-0264 | CVE-2016-7667 | plural Apple Product CoreText Service disruption in components (DoS) Vulnerabilities |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service via a crafted string. Apple iOS/macOS are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause a denial-of-service condition. Apple tvOS, iOS, and macOS Sierra are all products of Apple Inc. in the United States. Apple tvOS is a smart TV operating system; iOS is an operating system developed for mobile devices. CoreText is one of the text engines that can control text formatting and text layout. The following products and versions are affected: Apple tvOS prior to 10.1; iOS prior to 10.2; macOS Sierra prior to 10.12.2
| VAR-201702-0229 | CVE-2016-7630 | Apple iOS of WebSheet Vulnerabilities that bypass the sandbox protection mechanism in components |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebSheet" component, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors. This vulnerability allows remote attackers to escalate privileges on vulnerable installations of Apple iOS. User interaction is required to exploit this vulnerability in that the target must connect to a WiFi access point.The specific flaw exists within the usage of the legacy-diagnostics protocol handler. The issue lies in the launching of a diagnostic application that is able to render webpages outside of the sandbox. An attacker can leverage this vulnerability to escalate privileges outside the context of the sandbox. Apple iOS is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks. WebSheet is one of the web form application components
| VAR-201702-0188 | CVE-2016-7759 | Apple iOS of Springboard Vulnerability in which important information is obtained |
CVSS V2: 2.1 CVSS V3: 4.3 Severity: MEDIUM |
An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the "Springboard" component, which allows physically proximate attackers to obtain sensitive information by viewing application snapshots in the Task Switcher. Apple iOS is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to obtain sensitive information that may lead to further attacks. Springboard is a desktop for Apple iDevice
| VAR-201804-0506 | CVE-2017-6020 | LAquis SCADA Path traversal vulnerability |
CVSS V2: 4.0 CVSS V3: 5.3 Severity: MEDIUM |
Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level. Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA Contains a path traversal vulnerability.Information may be obtained. This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of LAquis SCADA Software. Authentication is not required to exploit this vulnerability.The specific flaw exists within global processing of requests inside the web server. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process. LAquis SCADA is a suite of SCADA software for monitoring and data acquisition. A security vulnerability exists in versions prior to LAquis SCADA 4.1.0.3237. LAquis SCADA Software is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input. This may aid in further attacks
| VAR-201706-0456 | CVE-2017-6026 |
Schneider Electric Modicon PLC Modicon M241 and M251 Vulnerability related to insufficient random values in firmware
Related entries in the VARIoT exploits database: VAR-E-201811-0126 |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised. Schneider-Electric Modicon M251 and others are programmable controller products from Schneider Electric. Security vulnerabilities exist in several Schneider Electric Modicon products.
Successfully exploiting these issues may allow attackers to obtain sensitive information or perform unauthorized actions. This may lead to other attacks
| VAR-201705-3185 | CVE-2017-6016 | LAquis SCADA Local Access Bypass Vulnerability |
CVSS V2: 4.4 CVSS V3: 7.3 Severity: HIGH |
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improper Access Control vulnerability has been identified, which may allow an authenticated user to modify application files to escalate privileges. LAquis SCADA is a tool and language for data collection, process monitoring, industrial automation, storage and reporting for quality management and application development. LAquis SCADA has a local access bypass vulnerability. With this vulnerability, an attacker can bypass unauthorized security operations by bypassing some security restrictions.
CVE-2017-6016 has been assigned to this vulnerability. A CVSS v3 base score
of 7.3 has been assigned; the CVSS vector string is
(AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Other vectors are
possible as well.
+++++
| VAR-201705-3541 | CVE-2017-6031 | Certec EDV GmbH atvise scada Cross-Site Scripting Vulnerability |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execution. Certec EDV GmbH atvise scada Contains an injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Certec EDV GmbH is headquartered in Austria. Atvise is a network-based human-machine interface monitoring and data acquisition system. Cross-site scripting vulnerability exists at Certec EDV GmbH atvise scada. An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an uninformed user of the affected site context. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks and to insert a crafted HTTP header into an HTTP response that could cause web server cache poisoning. These issues may aid in further attacks.
Versions prior to atvise 3.1 are vulnerable
| VAR-201705-3540 | CVE-2017-6029 | Certec Atvise scada Cross-Site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 5.4 Severity: MEDIUM |
A Cross-Site Scripting issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. This may allow remote code execution. Certec Atvise scada is a visual OPC UA-based SCADA solution from Certec EDV GmbH, Austria. The solution supports the use of Web technology to achieve hot backup redundancy and visualization of various plug-ins for Web browsers. A cross-site scripting vulnerability exists in Certec Atvise scada 3.0 and earlier. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks and to insert a crafted HTTP header into an HTTP response that could cause web server cache poisoning. These issues may aid in further attacks.
Versions prior to atvise 3.1 are vulnerable
| VAR-201805-0119 | CVE-2017-6015 | Rockwell Automation FactoryTalk Activation Local Privilege Escalation Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges on the system. CVSS v3 base score: 8.8, CVSS vector string: (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Rockwell Automation has released a new version of FactoryTalk Activation, Version 4.01, which addresses the identified vulnerability. Rockwell Automation recommends upgrading to the latest version of FactoryTalk Activation, Version 4.01 or later. Rockwell Automation FactoryTalk Activation Contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Rockwell Automation is a solution provider for industrial automation, control and information technology. A local privilege elevation vulnerability exists in RockwellAutomationFactoryTalkActivation.
FactoryTalk Activation Service 4.00.02 and prior are vulnerable. FactoryTalk Activation is one component used to manage application licenses
| VAR-201706-0455 | CVE-2017-6022 | BD PerformA and KLA Journal Service Vulnerabilities related to the use of hard-coded credentials |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of limited PHI/PII information stored in the BD Kiestra Database. The former is a set of applications for system monitoring; the latter is a set of applications for incremental backups.
An attacker can exploit this issue to obtain potentially sensitive information. Information obtained may aid in further attacks.
The following products are affected:
PerformA 2.0.14.0 and prior
| VAR-201705-3538 | CVE-2017-6025 | 3S-Smart Software Solutions GmbH CODESYS Web Server Buffer error vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by providing overly long strings to functions that handle the XML. Because the function does not verify string size before copying to memory, the attacker may then be able to crash the application or run arbitrary code. 3S-Smart Software Solutions CODESYS is a PLC (programmable controller) software programming tool from 3S-Smart Software Solutions, Germany
| VAR-201705-3539 | CVE-2017-6027 | CoDeSys Web Server arbitrary file upload vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow the upload of arbitrary files (with a dangerous type) to the CODESYS Web Server without authorization which may allow remote code execution. 3S-Smart Software Solutions GmbH CODESYS Web Server Contains a vulnerability related to unlimited uploads of dangerous types of files.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. 3S-Smart Software Solutions CODESYS is a PLC (programmable controller) software programming tool from 3S-Smart Software Solutions, Germany. An attacker could exploit this vulnerability to upload arbitrary files and execute arbitrary code