VARIoT IoT vulnerabilities database
| VAR-201310-0806 | No CVE | Arbitrary Commands Execution Vulnerability in JP1/Base |
CVSS V2: 8.3 CVSS V3: - Severity: High |
The JP1/Base contains a vulnerability where arbitrary commands may be executed when it receives request messages from unexpected hosts in the network.Malicious users can exploit this vulnerability to execute arbitrary commands by sending request messages from an unexpected host.
| VAR-201310-0299 | CVE-2013-4829 | plural HP Product FutureSmart Vulnerability to read images of arbitrary scanned documents on devices |
CVSS V2: 1.5 CVSS V3: - Severity: LOW |
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors. HP FutureSmart LaserJet Printers are laser printer devices from Hewlett Packard. HP FutureSmart LaserJet Printers has an unexplained defect that allows local attackers to exploit vulnerabilities to obtain sensitive information. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Note: the current version of the following document is available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/
docDisplay?docId=emr_na-c03888014
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c03888014
Version: 1
HPSBPI02892 rev.1 - Certain HP FutureSmart MFP, Weak PDF Encryption, Local
Disclosure of Information
NOTICE: The information in this Security Bulletin should be acted upon as
soon as possible.
Release Date: 2013-10-03
Last Updated: 2013-10-03
Potential Security Impact: Weak PDF encryption and local disclosure of
information
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with certain HP
FutureSmart LaserJet printers. The vulnerabilities might lead to weak
encryption of PDF documents or local disclosure of scanned information.
References: CVE-2013-4828 (SSRT101249)
CVE-2013-4829 (SSRT101327)
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed.
Please refer to the RESOLUTION
below for the list of impacted HP FutureSmart products.
BACKGROUND
CVSS 2.0 Base Metrics
===========================================================
Reference Base Vector Base Score
CVE-2013-4828 (AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.3
CVE-2013-4829 (AV:L/AC:M/Au:S/C:P/I:N/A:N) 1.5
===========================================================
Information on CVSS is documented
in HP Customer Notice: HPSN-2008-002
RESOLUTION
HP has provided updated printer firmware to resolve this issue, as referenced
in the following table. Browse to www.hp.com/go/support and
then:
Select "Drivers & Software"
Enter the HP product name listed in the table above into the search field
Click on "Search"
If the search returns a list of products click on the appropriate product
Under "Select operating system select your operating system, click "Next"
Under Select a Download Select "Firmware"
Click "Download" to obtain the Firmware
HISTORY
Version:1 (rev.1) - 3 October 2013 Initial release
Third Party Security Patches: Third party security patches that are to be
installed on systems running HP software products should be applied in
accordance with the customer's patch management policy.
Support: For issues about implementing the recommendations of this Security
Bulletin, contact normal HP Services support channel. For other issues about
the content of this Security Bulletin, send e-mail to security-alert@hp.com.
Report: To report a potential security vulnerability with any HP supported
product, send Email to: security-alert@hp.com
Subscribe: To initiate a subscription to receive future HP Security Bulletin
alerts via Email:
http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins
Security Bulletin Archive: A list of recently released Security Bulletins is
available here:
https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/
Software Product Category: The Software Product Category is represented in
the title by the two characters following HPSB.
3C = 3COM
3P = 3rd Party Software
GN = HP General Software
HF = HP Hardware and Firmware
MP = MPE/iX
MU = Multi-Platform Software
NS = NonStop Servers
OV = OpenVMS
PI = Printing and Imaging
PV = ProCurve
ST = Storage Software
TU = Tru64 UNIX
UX = HP-UX
Copyright 2013 Hewlett-Packard Development Company, L.P.
Hewlett-Packard Company shall not be liable for technical or editorial errors
or omissions contained herein. The information provided is provided "as is"
without warranty of any kind. To the extent permitted by law, neither HP or
its affiliates, subcontractors or suppliers will be liable for
incidental,special or consequential damages including downtime cost; lost
profits;damages relating to the procurement of substitute products or
services; or damages for loss of data, or software restoration. The
information in this document is subject to change without notice.
Hewlett-Packard Company and the names of Hewlett-Packard products referenced
herein are trademarks of Hewlett-Packard Company in the United States and
other countries. Other product and company names mentioned herein may be
trademarks of their respective owners.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)
iEYEARECAAYFAlJNoO0ACgkQ4B86/C0qfVnWUwCg72K9DXFme7VlPjA6yROdlz+F
cnAAoO0gEiP1K/DTFimE5+Qj55QJ2w3N
=0mV7
-----END PGP SIGNATURE-----
| VAR-201310-0475 | CVE-2013-5163 | Apple Mac OS X Directory Service Vulnerability that Prevents Password-Based Authentication |
CVSS V2: 6.6 CVSS V3: - Severity: MEDIUM |
Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrary Directory Services records via unspecified vectors. Apple Mac OS X is prone to a local security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Apple Mac OS X 10.8 through versions 10.8.5 are vulnerable. The issue was addressed through
improved credential validation.
CVE-ID
CVE-2013-5163 : the rookies of 42
OS X v10.8.5 Supplemental Update may be obtained from
the Software Update pane in System Preferences, or Apple's Software
Downloads web site: http://www.apple.com/support/downloads/
Fox OS X Mountain Lion v10.8.5
The download file is named: OSXUpd10.8.5Supp.dmg
Its SHA-1 digest is: 18636c06f0db5b326752628fb7a2dfa3ce077ae1
For OS X Mountain Lion v10.8.4
The download file is named: OSXUpd10.8.5.dmg
Its SHA-1 digest is: b115881f8541b2b80f89ff0e37563f2245be445b
For OS X Mountain Lion v10.8 and v10.8.3
The download file is named: OSXUpdCombo10.8.5.dmg
Its SHA-1 digest is: 5f574ec77678a965f4684d176ec13014d9ffac75
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQIcBAEBAgAGBQJSTc6mAAoJEPefwLHPlZEwnZIQAJePLWS/A44WfcbaARuIbWWH
oBlV13t3iD6gEqsvICNb/XZU5EG/4zSfDKt9gBgpsHR/jcQ8+FNFL2wiu1q/POAv
Ecnx8p0oZVFrdL7dVe19TOitc/AleAkgr7E0/efp7tvxcK2B035N+Dc5SHdUVX/9
S9z3pF178Pl0akiMWI2c+iYcAHt1a1SIqTHOLnJlNr1RpIHkZork5uTrpjLl3qs4
7m/fjBg2JLqb6q6IlmyBviFI4StMUd+tPHZ23qPwnUL8L/x2H36566yA03hghsEc
1ZPatK3O+FHoVVgE8q/9GTH/42dG8K5wtF/xqpbyLqTVO79swjmIxW6vhZPXbmqW
LBDeZVEx6pvp7qWRlmqyvX2Bl3IuCRp4K8qHN4HsU8F8zko2wviHOyPU4TsB7gEI
xsETCtvVLLhImVoJF2Y9vLeAkWazqPIOlFFepeKcNSrN3L02hT3qQXXtZa4fTLON
xDYTnHVt8xjTmaApLLYc3jXaeRX03IekGW2cduEwkAvKuOZvh5lQI5OT22qWDgsN
3EaliNghCV7ActzQL8kTzkCOpSB9H34bkwGv5/rbEGQnOn6ROLB6JYuHX11lyJ/Z
/Bxn2Jfao3+FR2e8Xp07Z9RHFocwOduGtJziAj3WKjCvw8JzBROqchupsXkVUp6+
v8MP/bVYJ8LepQJm81IK
=VYQW
-----END PGP SIGNATURE-----
| VAR-201310-0394 | CVE-2013-5967 | AlienVault Open Source Security Information Management In SQL Injection vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/. (1) radar-iso27001-potential.php (2) radar-iso27001-A12IS_acquisition-pot.php (3) radar-iso27001-A11AccessControl-pot.php (4) radar-iso27001-A10Com_OP_Mgnt-pot.php (5) radar-pci-potential.php. The Triangle Research Nano-10 PLC is a controller for automated manufacturing. The Triangle Research Nano-10 PLC has a remote denial of service attack when processing specially crafted messages, allowing remote attackers to crash applications. This vulnerability can be triggered when the firmware is processing a special length (over 0x200) MODBUS TCP message on TCP port 502. Open Source SIEM (OSSIM) is prone to multiple SQL-injection vulnerabilities.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Open Source SIEM (OSSIM) 4.3.0 and prior are vulnerable
| VAR-201310-0532 | CVE-2013-5503 | Cisco IOS XR Software UDP Packet Denial of Service Vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413. ( Memory consumption ) There is a vulnerability that can be exploited. Cisco IOS XR is a member of the Cisco IOS Software family that uses a microkernel-based operating system architecture. The device cannot allocate memory for packets, causing a denial of service attack.
An attacker can exploit this issue to exhaust all available memory and cause a denial-of-service condition.
This issue is being tracked by Cisco Bug ID CSCue69413
| VAR-201404-0194 | CVE-2014-1990 | TOSHIBA TEC e-Studio series vulnerable to cross-site request forgery |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authentication of administrators for requests that change passwords. e-Studio provided by TOSHIBA TEC CORPORATION is a multi-function peripheral (MFP). As a result, a remote attacker may obtain the document assets such as scan data. TOSHIBA e-Studio is prone to a cross-site request-forgery vulnerability.
Exploiting the issue will allow a remote attacker to use a victim's currently active session to change the victim's password. Successful exploits will compromise affected computers. TOSHIBA TEC e-Studio 232, 233, 282 and 283 are all printing and copying all-in-one products of Japan's Toshiba (TOSHIBA). TopAccess (also known as Web-based management tool) is the network management software used in these products
| VAR-201310-0503 | CVE-2013-5519 | Cisco Wireless LAN Controller Cross-site scripting vulnerability in device management interface |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in the management interface on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuf77810.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
This issue is being tracked by Cisco Bug ID CSCuf77810
| VAR-201310-0721 | No CVE | IBC Solar ServeMaster TLP+ 'setup_comm_smtp.tcl' has multiple information disclosure vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
IBC Solar ServeMaster TLP+ contains a security vulnerability in /cgi-bin/setup_comm_smtp.tcl that allows authentication credentials to be sent in clear text over HTTP, allowing an attacker to obtain SMTP server authentication information. IBC Solar ServeMaster TLP + is an inverter device for photovoltaic power generation system of IBC Solar, Germany.
An information disclosure vulnerability exists in IBC Solar ServeMaster TLP +. Attackers can use this vulnerability to gain access to sensitive information by sniffing the network. Successful exploits will lead to other attacks
| VAR-201310-0705 | No CVE | IBC Solar ServeMaster TLP+ WEB Interface Default Account Vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The IBC Solar ServeMaster TLP+ WEB interface has a default account and the 'admin' password is 'admin', allowing an attacker to gain access to the device using that account. IBC Solar ServeMaster TLP + is an inverter device for photovoltaic power generation system of IBC Solar, Germany.
A security bypass vulnerability exists in IBC Solar ServeMaster TLP +, which originates from the use of hard-coded certificates for programs. A remote attacker could use this vulnerability to gain access to an affected device
| VAR-201310-0543 | CVE-2013-5517 | Cisco Unified Communications Domain Manager of Web In the framework SQL Injection vulnerability |
CVSS V2: 5.5 CVSS V3: - Severity: MEDIUM |
SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567.
Exploiting this issue could allow an authenticated attacker to compromise the affected application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID CSCuh96567. This component features scalable, distributed, and highly available enterprise Voice over IP call processing
| VAR-201310-0390 | CVE-2013-5944 | Siemens SCALANCE X-200 and X-200IRT Vulnerability to execute administrator actions in switch firmware |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface. The Siemens Scalance X200 is an industrial Ethernet switch from Siemens. SCALANCE X-200 and X-200IRT series switches are prone to an authentication-bypass vulnerability.
Successfully exploiting this issue may allow an attacker to bypass certain security restrictions and gain administrative access to the affected device.
The following products are affected.
SCALANCE X-200 running firmware versions prior to 4.5.0
SCALANCE X-200IRT running firmware versions prior to 5.1.0
| VAR-201309-0573 | No CVE | Tenda W309R Router Cookie Verification Bypass Vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The Tenda W309R Router WEB console does not have a correct COOKIE management mechanism, which allows an attacker to access the router device without providing a password. Tenda W309R is a wireless router product from China's Tenda.
An authentication bypass vulnerability exists in the Tenda W309R router. An attacker could use this vulnerability to gain access to affected devices and sensitive information. There are vulnerabilities in Tenda W309R version 5.07.46, other versions may also be affected
| VAR-201310-0803 | No CVE | Unknown arbitrary command execution vulnerability in Hitachi JP1 / Base |
CVSS V2: 4.6 CVSS V3: - Severity: MEDIUM |
Hitachi JP1 is a solution that monitors the execution of business and centrally manages system content such as OS and applications.
Hitachi JP1 / Base has an unknown vulnerability in processing messages sent by some hosts, allowing remote attackers to use the vulnerability to execute arbitrary commands. Hitachi JP1/Base is prone to an unspecified arbitrary command-execution vulnerability.
Local attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application
| VAR-201309-0572 | No CVE | Unknown arbitrary command execution vulnerability in Hitachi JP1 / Automatic Job Management System |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
Hitachi JP1 is a solution that monitors the execution of business and centrally manages system content such as OS and applications. Hitachi JP1 / Automatic Job Management System is a set of job management systems from Hitachi, Japan. The system supports scheduling, job error notifications, and visualization of job health.
A remote arbitrary command execution vulnerability exists in Hitachi JP1 / Automatic Job Management System. An attacker could use this vulnerability to execute arbitrary commands in the context of an affected application
| VAR-201310-0017 | CVE-2012-4102 | Cisco Unified Computing System Authenticated Vulnerability in Fabric Interconnect Component |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The activate firmware command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq02600. Cisco Unified Computing System is prone to a local arbitrary command-execution vulnerability.
A local attacker can exploit this issue to execute arbitrary commands on the Linux shell with root privileges. Successful exploits may completely compromise the affected device.
This issue is being tracked by Cisco Bug ID CSCtq02600. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology
| VAR-201310-0018 | CVE-2012-4103 | Cisco Unified Computing System Authenticated Vulnerability in Fabric Interconnect Component |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
ethanalyzer in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq02686. Cisco Unified Computing System (UCS) Of fabric interconnect components ethanalyzer Contains a privileged vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with elevated privileges. Successful exploits may compromise the affected device.
This issue is being tracked by Cisco Bug ID CSCtq02686. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology. A security vulnerability exists in the 'ethanalyzer' command in the fabric-interconnect component of Cisco UCS due to the program not properly filtering user-submitted input
| VAR-201310-0019 | CVE-2012-4104 | Cisco Unified Computing System Absolute path traversal vulnerability in fabric interconnect components |
CVSS V2: 6.6 CVSS V3: - Severity: MEDIUM |
Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary files via a full pathname in an image header, aka Bug ID CSCtq02706. Cisco Unified Computing System is prone to a directory-traversal vulnerability.
Exploiting this issue will allow a local attacker to modify or delete arbitrary files on the filesystem.
This issue is tracked by Cisco BugID CSCtq02706. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology
| VAR-201310-0024 | CVE-2012-4109 | Cisco Unified Computing System Authenticated Vulnerability in Fabric Interconnect Component |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The clear sshkey command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86559.
A local attacker can exploit this issue to execute arbitrary commands with root privileges. Successful exploits may compromise the affected device.
This issue is being tracked by Cisco Bug ID CSCtq86559. Cisco Unified Computing System (UCS) is a unified computing system of Cisco (Cisco). The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology
| VAR-201310-0025 | CVE-2012-4110 | Cisco Unified Computing System Authenticated Vulnerability in Fabric Interconnect Component |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
run-script in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86560. Cisco Unified Computing System (UCS) Of fabric interconnect components run-script Contains a privileged vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with root privileges. Successful exploits may compromise the affected device.
This issue being tracked by Cisco Bug ID CSCtq86560. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology. A security vulnerability exists in the 'run-script' command in the fabric-interconnect component of Cisco UCS due to the program not properly filtering user-submitted input
| VAR-201310-0026 | CVE-2012-4111 | Cisco Unified Computing System Authenticated Vulnerability in Fabric Interconnect Component |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The create certreq command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86563. Cisco Unified Computing System is prone to a local command-injection vulnerability.
A local attacker can exploit this issue to execute arbitrary commands with root privileges. Successful exploits may compromise the affected device.
This issue being tracked by Cisco Bug ID CSCtq86563. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology