VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201309-0033 CVE-2013-1117 Cisco WebEx Recording Format player Exception Handler Buffer Overflow Vulnerability CVSS V2: 9.3
CVSS V3: -
Severity: HIGH
Buffer overflow in the exception handler in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCuc27639. Cisco WebEx WRF Player is prone to a remote memory-corruption vulnerability. An attacker could exploit this issue to crash the affected player causing denial-of-service conditions or execute arbitrary code in context of the user. This issue is being tracked by Cisco Bug ID CSCuc27639. The following versions are affected: 27.11.26, 27.21.10, 27.25.10, 27.32.1, 27.32.10, 28.4, 28.0.0
VAR-201309-0034 CVE-2013-1118 Cisco WebEx Recording Format player Vulnerable to stack-based buffer overflow CVSS V2: 9.3
CVSS V3: -
Severity: HIGH
Stack-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCuc27645. Vendors have confirmed this vulnerability Bug ID CSCuc27645 It is released as.Skillfully crafted by a third party WRF An arbitrary code may be executed via the file. An attacker can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in denial-of-service conditions. This issue is being tracked by Cisco Bug ID CSCuc27645. The vulnerability stems from the software not properly handling .wrf files. The following versions are affected: 27.11.26, 27.21.10, 27.25.10, 27.32.1, 27.32.10, 28.4, 28.0.0
VAR-201309-0035 CVE-2013-1119 Cisco WebEx Recording Format player Vulnerable to buffer overflow CVSS V2: 9.3
CVSS V3: -
Severity: HIGH
Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT index value in JPEG data within a WRF file, aka Bug ID CSCuc24503. Cisco WebEx Recording Format (WRF) player Contains a buffer overflow vulnerability. An attacker could exploit this issue to crash the affected player causing denial-of-service conditions or execute arbitrary code in context of the user. This issue is being tracked by Cisco Bug ID CSCuc24503. The following versions are affected: 27.11.26, 27.21.10, 27.25.10, 27.32.1, 27.32.10, 28.4, 28.0.0
VAR-201309-0296 CVE-2013-5471 Cisco Global Site Selector of Web Cross-site request forgery vulnerability in framework CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh42164. Vendors have confirmed this vulnerability Bug ID CSCuh42164 It is released as.A third party may be able to hijack the authentication of any user. Attackers can exploit this issue to perform certain administrative actions and to gain unauthorized access to the affected application. This issue is being tracked by Cisco bug ID CSCuh42164. The product optimizes site selection, improves DNS response and ensures data center availability. An attacker could exploit this vulnerability to convince users of an affected system to follow a malicious link or visit an attacker-controlled website. This vulnerability could be exploited with user privileges to submit arbitrary requests to an affected device
VAR-201309-0019 CVE-2012-5990 Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) vulnerable to cross-site scripting (XSS) CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor Login pages in Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud18375. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCud18375. Remote attackers can exploit this vulnerability to inject arbitrary Web scripts or HTML into user pages
VAR-201309-0295 CVE-2013-5470 Cisco Secure Access Control System Service disruption in (DoS) Vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID CSCuh12488. Vendors have confirmed this vulnerability Bug ID CSCuh12488 It is released as.Malformed by a third party TCP Service disruption via packets ( Process crash ) There is a possibility of being put into a state. Cisco Secure Access Control System is prone to a remote denial-of-service vulnerability. Attackers can exploit this issue to crash a runtime process, resulting in denial-of-service conditions. This issue is being tracked by Cisco Bug ID CSCuh12488. The system can respectively control network access and network device access through RADIUS and TACACS protocols
VAR-201309-0590 No CVE There are multiple unspecified vulnerabilities in NetGear RAIDiator CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
NetGear RAIDiator is a direct-hanging storage device based on Linux and debian-sparc platforms. There are several security vulnerabilities in NetGear RAIDiator: 1. There are many unspecified errors in the CIFS service. 2. There are multiple unspecified errors in the DLNA service. 3. There are several unspecified errors in the iTunes service. 4, Frontview has multiple unspecified errors. No detailed vulnerability details are currently available.
VAR-201309-0600 No CVE RuggedCom Rugged Operating System Remote Security Bypass Vulnerability CVSS V2: -
CVSS V3: -
Severity: -
Rugged Operating System is prone to a security-bypass vulnerability. An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions. Rugged Operating System prior to 3.12.2 are vulnerable.
VAR-201308-0508 No CVE Cogent DataHub Unspecified Arbitrary File Overwrite and Denial Of Service Vulnerabilities CVSS V2: -
CVSS V3: -
Severity: -
Cogent DataHub is prone to an unspecified arbitrary-file-overwrite vulnerability and multiple unspecified denial-of-service vulnerabilities. Attackers can leverage these issues to overwrite arbitrary files on the victim's computer in the context of the vulnerable application, crash the application that uses the affected library, denying service to legitimate users. Limited information is currently available regarding this issue. We will update this BID as more information emerges. Versions prior to Cogent DataHub 7.3.3 are vulnerable.
VAR-201309-0232 CVE-2013-3469 Cisco Mobility service Vulnerability to get unauthorized session in engine CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug ID CSCue50794. Cisco Mobility Services Engine is prone to a security-bypass vulnerability. Exploiting this issue could allow an attacker to bypass certain security restrictions and perform unauthorized actions. This may aid in further attacks. This issue is being tracked by Cisco Bug ID CSCue50794. The platform collects, stores and manages data from wireless clients, Cisco access points and controllers. A security bypass vulnerability exists in Cisco MSE due to a misconfigured Oracle SSL server
VAR-201308-0219 CVE-2013-3474 Cisco Wireless LAN Controller Device Web Service disruption in the administrator interface (DoS) Vulnerabilities CVSS V2: 6.3
CVSS V3: -
Severity: MEDIUM
The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to cause a denial of service (device crash) by leveraging membership in the Full Manager managers group, Read Only managers group, or Lobby Ambassador managers group, and sending a request that (1) lacks a parameter value or (2) contains a malformed parameter value, aka Bug IDs CSCuh14313, CSCuh14159, CSCuh14368, and CSCuh14436. Cisco Wireless LAN Controller (WLC) Runs on the device Web Administrator interface includes service disruption ( Device crash ) There are vulnerabilities that are put into a state. The Cisco WLC is responsible for system-wide wireless LAN functions such as security policy, intrusion protection, RF management, quality of service, and mobility. An attacker with any Full Manager, Read Only, and Lobby Ambassador manager group member accounts is authenticated and submits a request to the affected device. The request contains missing values or malformed values for specific parameters, which can cause the device to reboot. When it crashes, an authenticated remote attacker can exploit this vulnerability to cause a denial of service. These issues are being tracked by Cisco Bug IDs CSCuh14313, CSCuh14159, CSCuh14368, and CSCuh14436. The vulnerability is caused by the program not properly filtering parameters
VAR-201308-0305 CVE-2013-5469 Cisco IOS of TCP Service disruption in implementations (DoS) Vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED state, which allows remote attackers to cause a denial of service (flood of ACK packets) via a crafted series of ACK and FIN packets, aka Bug ID CSCtz14399. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. This vulnerability stems from an error closing an established TCP connection. Cisco IOS is prone to a remote denial-of-service vulnerability. Exploiting this issue may allow remote attackers to trigger denial-of-service conditions. This issue is being tracked by Cisco Bug ID CSCtz14399
VAR-201308-0460 No CVE TP-LINK TD-W8951ND Router has multiple input validation vulnerabilities CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
The TP-LINK TD-W8951ND Router is a wireless router device. TP-LINK TD-W8951ND Router Firmware 4.0.0 Build 120607 Release 30923 has multiple cross-site scripting and cross-site request forgery vulnerabilities. Allows an attacker to exploit a vulnerability to obtain sensitive information or hijack a user's session: 1. Incorrect handling of the Referer field without a URL, allowing unauthenticated attackers to exploit the vulnerability for a reflective cross-site scripting vulnerability. 2. The \"home_wlan_1\" parameter is incorrectly handled, allowing authenticated attackers to exploit vulnerabilities for reflective cross-site scripting vulnerabilities. 3. There are multiple cross-site request forgery attacks, allowing the attacker to construct a malicious URI, enticing the login user to resolve, and performing malicious operations in the target user context, such as resetting the administrator password. Attackers can use these vulnerabilities to execute arbitrary script code in the context of the affected site. They can steal cookie-based authentication, perform unauthorized operations, leak or modify sensitive information, and there may be other forms of attacks. There are vulnerabilities in TP-Link TD-W8951ND 4.0.0 Build 120607.Rel. 30923, other versions may also be affected. Other attacks may also be possible. ----------- Author: ----------- xistence < xistence[at]0x90[.]nl > ------------------------- Affected products: ------------------------- Tested on TP-Link TD-W8951ND Firmware 4.0.0 Build 120607 Rel.30923 ------------------------- Affected vendors: ------------------------- TP-Link http://www.tp-link.com/ ---------- Details: ---------- [ 0x01 - Unauthenticated Reflected XSS in Referer for non-existing url pages ] GET /doesnotexist HTTP/1.1 Host: <IP> Referer: http://pwned"><script>alert("XSS")</script> Connection: keep-alive [ 0x02 - Authenticated Reflected XSS in "home_wlan_1" arguments ] http:// <IP>/Forms/home_wlan_1?wlanWEBFlag=%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E http:// <IP>/Forms/home_wlan_1?AccessFlag=%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E http:// <IP>/Forms/home_wlan_1?wlan_APenable=%3Cscript%3Ealert%28%22XSS%22%29%3C/script%3E [ 0x03 - Authenticated XSS in diagnostics (ping) "/Forms/tools_test_1" argument "PingIPAddr" ] POST /Forms/tools_test_1 HTTP/1.1 Host: <IP> Referer: http://<IP>/maintenance/tools_test.htm Authorization: Basic blablabla== Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 164 Test_PVC=PVC0&PingIPAddr=%3C%2Ftextarea%3E%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E&pingflag=1&trace_open_flag=0&InfoDisplay=Ping+request+could+not+find+host+ [ 0x04 - Reset Admin password CSRF ] http:// <IP>/Forms/tools_admin_1?uiViewTools_Password=PWNED&uiViewTools_PasswordConfirm=PWNED -------------- Timeline: -------------- 2013-05-30 Provided details to TP-Link. 2013-06-01 Response from TP-Link that they will try to fix it. 2013-07-31 No further response, mailed again to ask for status. 2013-08-30 No response, public disclosure
VAR-201309-0235 CVE-2013-3607 Supermicro IPMI based on ATEN firmware contain multiple vulnerabilities

Related entries in the VARIoT exploits database: VAR-E-201308-0403
CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi. Supermicro IPMI is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data. An attacker can exploit these issues to execute arbitrary code in the context of the device that uses the affected interface. Failed exploit attempts will likely crash the device
VAR-201309-0164 CVE-2013-3608 Supermicro IPMI based on ATEN firmware contain multiple vulnerabilities CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi. Supermicro IPMI Web Interface is prone to an unspecified remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data
VAR-201309-0165 CVE-2013-3609 Supermicro IPMI based on ATEN firmware contain multiple vulnerabilities CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function. Supermicro Intelligent Platform Management Interface (IPMI) implementations based on ATEN firmware contain multiple vulnerabilities in their web management interface. Supermicro IPMI Web Interface is prone to a remote privilege-escalation vulnerability because it fails to adequately sanitize user-supplied input data. Remote attackers can exploit this issue to gain elevated privileges and perform unauthorized actions
VAR-201308-0211 CVE-2013-3463 Cisco Adaptive Security Appliances Device protocol-inspection Service disruption in functionality (DoS) Vulnerabilities CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle timeout, which allows remote attackers to cause a denial of service (connection-table exhaustion) via crafted requests that use an inspected protocol, aka Bug ID CSCuh13899. Vendors have confirmed this vulnerability Bug ID CSCuh13899 It is released as.Denial of service by a third party via crafted request using inspected protocol ( Connection table exhaustion ) There is a possibility of being put into a state. Cisco Adaptive Security Appliance is prone to a denial-of-service vulnerability. A remote attacker may exploit this issue to cause denial-of-service conditions. This issue is being tracked by Cisco Bug IDs CSCuh13899
VAR-201308-0214 CVE-2013-3467 Cisco UCS Running on any fabric interconnect device CLI Service disruption in components (DoS) Vulnerabilities CVSS V2: 4.6
CVSS V3: -
Severity: MEDIUM
Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain situations that lack a SPAN session, allows local users to cause a denial of service (memory consumption and device reset) via a (1) "show monitor session all" or (2) "show monitor session" command, aka Bug ID CSCug20103. Cisco Unified Computing System is prone to multiple local denial-of-service vulnerabilities. Local attacker can exploit these issues to cause an affected device to reload or become unresponsive, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCug20103. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology. The vulnerability is caused by not releasing memory after executing CLI commands and not configuring a SPAN session
VAR-201308-0216 CVE-2013-3470 Cisco IOS XR of RIP Service disruption in the process (DoS) Vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731. Cisco IOS XR is a member of the Cisco IOS Software family that uses a microkernel-based operating system architecture. The RIP process crashes because the attacker does not correctly verify the message input and allows the attacker to send a special RIP Version 2 message. An attacker can exploit this issue to cause the RIP process to crash on an affected device, resulting in a denial-of-service condition. This issue is being tracked by Cisco Bug IDs CSCue46731
VAR-201308-0007 CVE-2012-5744 Cisco Identity Services Engine Software guest portal cross-site scripting vulnerability CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the guest portal in Cisco Identity Services Engine (ISE) Software allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCud11139 and CSCug02904. Vendors have confirmed this vulnerability Bug ID CSCud11139 and CSCug02904 It is released as.By any third party Web Script or HTML May be inserted. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. These issues are being tracked by Cisco Bug IDs CSCud11139 and CSCug02904. The platform monitors the network by collecting real-time information on the network, users and devices, and formulating and implementing corresponding policies. A remote attacker could exploit these vulnerabilities to inject arbitrary Web script or HTML