VARIoT IoT vulnerabilities database
| VAR-202402-1390 | CVE-2023-48363 | in multiple Siemens products NULL Pointer dereference vulnerability |
CVSS V2: 6.1 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC Route Control V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versions < V18 Update 4), SIMATIC WinCC Runtime Professional V19 (All versions < V19 Update 2), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions < V7.5 SP2 Update 15), SIMATIC WinCC V8.0 (All versions < V8.0 Update 4). The implementation of the RPC (Remote Procedure call)
communication protocol in the affected products do not
properly handle certain unorganized RPC messages. An
attacker could use this vulnerability to cause a denial of service
condition in the RPC server. openpcs 7 , SIMATIC BATCH , SIMATIC PCS 7 For multiple Siemens products, NULL There is a vulnerability in pointer dereference.Service operation interruption (DoS) It may be in a state. SIMATIC PCS 7 is a distributed control system (DCS) that integrates SIMATIC WinCC, SIMATIC Batch, SIMATIC Route control, OpenPCS 7 and other components. SIMATIC WinCC is a supervisory control and data acquisition (SCADA) system. SIMATIC WinCC Runtime Professional is a visual runtime platform for operator control and monitoring of machines and plants
| VAR-202402-1534 | CVE-2024-21404 | Microsoft's .NET and Microsoft Visual Studio Service operation interruption in (DoS) Vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
.NET Denial of Service Vulnerability. Microsoft's .NET and Microsoft Visual Studio includes denial of service (DoS) Vulnerability exists.Service operation interruption (DoS) It may be in a state. ==========================================================================
Ubuntu Security Notice USN-6634-1
February 13, 2024
dotnet6, dotnet7, dotnet8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in .NET.
Software Description:
- dotnet6: dotNET CLI tools and runtime
- dotnet7: dotNET CLI tools and runtime
- dotnet8: dotNET CLI tools and runtime
Details:
Brennan Conroy discovered that .NET with SignalR did not properly
handle malicious clients. An attacker could possibly use this issue
to cause a denial of service. (CVE-2024-21386)
Bahaa Naamneh discovered that .NET with OpenSSL support did not
properly parse X509 certificates. An attacker could possibly use
this issue to cause a denial of service. (CVE-2024-21404)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
aspnetcore-runtime-6.0 6.0.127-0ubuntu1~23.10.1
aspnetcore-runtime-7.0 7.0.116-0ubuntu1~23.10.1
aspnetcore-runtime-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-host 6.0.127-0ubuntu1~23.10.1
dotnet-host-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-host-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-hostfxr-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-hostfxr-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-hostfxr-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-runtime-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-runtime-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-runtime-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-sdk-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-sdk-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-sdk-8.0 8.0.102-0ubuntu1~23.10.1
dotnet6 6.0.127-0ubuntu1~23.10.1
dotnet7 7.0.116-0ubuntu1~23.10.1
dotnet8 8.0.102-8.0.2-0ubuntu1~23.10.1
Ubuntu 22.04 LTS:
aspnetcore-runtime-6.0 6.0.127-0ubuntu1~22.04.1
aspnetcore-runtime-7.0 7.0.116-0ubuntu1~22.04.1
aspnetcore-runtime-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-host 6.0.127-0ubuntu1~22.04.1
dotnet-host-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-host-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-hostfxr-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-hostfxr-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-hostfxr-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-runtime-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-runtime-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-runtime-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-sdk-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-sdk-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-sdk-8.0 8.0.102-0ubuntu1~22.04.1
dotnet6 6.0.127-0ubuntu1~22.04.1
dotnet7 7.0.116-0ubuntu1~22.04.1
dotnet8 8.0.102-8.0.2-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes.
The following advisory data is extracted from:
https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_1552.json
Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment.
- Packet Storm Staff
====================================================================
Red Hat Security Advisory
Synopsis: Important: .NET 6.0 security update
Advisory ID: RHSA-2024:1552-03
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2024:1552
Issue date: 2024-03-28
Revision: 03
CVE Names: CVE-2024-21404
====================================================================
Summary:
An update for .NET 6.0 is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description:
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.127 and .NET Runtime 6.0.27.
Security Fix(es):
* dotnet: Denial of Service in X509Certificate2 (CVE-2024-21404)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Solution:
https://access.redhat.com/articles/11258
CVEs:
CVE-2024-21404
References:
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2263086
| VAR-202402-1535 | CVE-2024-21386 | Microsoft's Microsoft Visual Studio and ASP.NET Core Service operation interruption in (DoS) Vulnerability Stated |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
.NET Denial of Service Vulnerability. Microsoft's Microsoft Visual Studio and ASP.NET Core for, .NET Service operation is interrupted due to a defect in (DoS) A state vulnerability exists.Service operation interruption (DoS) It may be in a state.
The following advisory data is extracted from:
https://access.redhat.com/security/data/csaf/v2/advisories/2024/rhsa-2024_0814.json
Red Hat officially shut down their mailing list notifications October 10, 2023. Due to this, Packet Storm has recreated the below data as a reference point to raise awareness. It must be noted that due to an inability to easily track revision updates without crawling Red Hat's archive, these advisories are single notifications and we strongly suggest that you visit the Red Hat provided links to ensure you have the latest information available if the subject matter listed pertains to your environment.
- Packet Storm Staff
====================================================================
Red Hat Security Advisory
Synopsis: Important: .NET 6.0 security, bug fix, and enhancement update
Advisory ID: RHSA-2024:0814-03
Product: .NET Core on Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2024:0814
Issue date: 2024-02-14
Revision: 03
CVE Names: CVE-2024-21386
====================================================================
Summary:
An update for .NET 6.0 is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description:
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 6.0.127 and .NET Runtime 6.0.27.
The following packages have been upgraded to a later upstream version: rh-dotnet60-dotnet (6.0.127). (BZ#2262321)
Security Fix(es):
* dotnet: Denial of Service in SignalR server (CVE-2024-21386)
* dotnet: Denial of Service in X509Certificate2 (CVE-2024-21404)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Solution:
https://access.redhat.com/articles/11258
CVEs:
CVE-2024-21386
References:
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2263085
https://bugzilla.redhat.com/show_bug.cgi?id=2263086
. ==========================================================================
Ubuntu Security Notice USN-6634-1
February 13, 2024
dotnet6, dotnet7, dotnet8 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 23.10
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in .NET.
Software Description:
- dotnet6: dotNET CLI tools and runtime
- dotnet7: dotNET CLI tools and runtime
- dotnet8: dotNET CLI tools and runtime
Details:
Brennan Conroy discovered that .NET with SignalR did not properly
handle malicious clients. An attacker could possibly use this issue
to cause a denial of service. (CVE-2024-21386)
Bahaa Naamneh discovered that .NET with OpenSSL support did not
properly parse X509 certificates. An attacker could possibly use
this issue to cause a denial of service. (CVE-2024-21404)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 23.10:
aspnetcore-runtime-6.0 6.0.127-0ubuntu1~23.10.1
aspnetcore-runtime-7.0 7.0.116-0ubuntu1~23.10.1
aspnetcore-runtime-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-host 6.0.127-0ubuntu1~23.10.1
dotnet-host-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-host-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-hostfxr-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-hostfxr-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-hostfxr-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-runtime-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-runtime-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-runtime-8.0 8.0.2-0ubuntu1~23.10.1
dotnet-sdk-6.0 6.0.127-0ubuntu1~23.10.1
dotnet-sdk-7.0 7.0.116-0ubuntu1~23.10.1
dotnet-sdk-8.0 8.0.102-0ubuntu1~23.10.1
dotnet6 6.0.127-0ubuntu1~23.10.1
dotnet7 7.0.116-0ubuntu1~23.10.1
dotnet8 8.0.102-8.0.2-0ubuntu1~23.10.1
Ubuntu 22.04 LTS:
aspnetcore-runtime-6.0 6.0.127-0ubuntu1~22.04.1
aspnetcore-runtime-7.0 7.0.116-0ubuntu1~22.04.1
aspnetcore-runtime-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-host 6.0.127-0ubuntu1~22.04.1
dotnet-host-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-host-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-hostfxr-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-hostfxr-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-hostfxr-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-runtime-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-runtime-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-runtime-8.0 8.0.2-0ubuntu1~22.04.1
dotnet-sdk-6.0 6.0.127-0ubuntu1~22.04.1
dotnet-sdk-7.0 7.0.116-0ubuntu1~22.04.1
dotnet-sdk-8.0 8.0.102-0ubuntu1~22.04.1
dotnet6 6.0.127-0ubuntu1~22.04.1
dotnet7 7.0.116-0ubuntu1~22.04.1
dotnet8 8.0.102-8.0.2-0ubuntu1~22.04.1
In general, a standard system update will make all the necessary changes
| VAR-202402-0387 | CVE-2024-1431 | of netgear R7000 Firmware vulnerabilities |
CVSS V2: 3.3 CVSS V3: 4.3 Severity: MEDIUM |
A vulnerability was found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this issue is some unknown functionality of the file /debuginfo.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-253382 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Netgear R7000 is a Netgear dual-band Gigabit wireless router. A remote attacker can use this vulnerability to submit special requests and obtain sensitive information
| VAR-202402-0401 | CVE-2024-1430 | of netgear R7000 Firmware vulnerabilities |
CVSS V2: 3.3 CVSS V3: 4.3 Severity: Medium |
A vulnerability has been found in Netgear R7000 1.0.11.136_10.2.120 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /currentsetting.htm of the component Web Management Interface. The manipulation leads to information disclosure. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The identifier VDB-253381 was assigned to this vulnerability
| VAR-202402-0623 | CVE-2024-24321 | D-Link Systems, Inc. of DIR-816 Command injection vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function. D-Link Systems, Inc. of DIR-816 Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202402-1506 | CVE-2023-43017 | IBM of Security Verify Access Certificate validation vulnerabilities in |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155. (DoS) It may be in a state
| VAR-202402-1982 | CVE-2023-32330 | IBM of Security Verify Access Certificate validation vulnerabilities in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977. (DoS) It may be in a state
| VAR-202402-1514 | CVE-2023-32328 | IBM of Security Verify Access Vulnerability in plaintext transmission of important information in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957. IBM of Security Verify Access Contains a vulnerability in the transmission of important information in clear text.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202402-0523 | CVE-2024-22012 | Google of Android Out-of-bounds write vulnerability in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Google of Android Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Google Pixel is a smartphone made by the American company Google.
Google Pixel has a buffer overflow vulnerability caused by a lack of bounds checking. An attacker could exploit this vulnerability to escalate privileges
| VAR-202402-0660 | CVE-2023-47209 | TP-LINK Technologies of er7206 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. TP-LINK Technologies of er7206 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK ER7206 is a multifunctional Gigabit router from China TP-LINK Company.
TP-LINK ER7206 1.3.0 build 20230322 Rel.70591 version has an operating system command injection vulnerability
| VAR-202402-0356 | CVE-2023-47167 | TP-LINK Technologies of er7206 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. TP-LINK Technologies of er7206 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK ER7206 is a multifunctional Gigabit router from China TP-LINK Company.
TP-LINK ER7206 1.3.0 build 20230322 Rel.70591 version has an operating system command injection vulnerability
| VAR-202402-0339 | CVE-2023-46683 | TP-LINK Technologies of er7206 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability. TP-LINK Technologies of er7206 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK ER7206 is a multifunctional Gigabit router from China TP-LINK Company.
There is an input validation vulnerability in the TP-LINK ER7206 wireguard VPN configuration. A remote attacker can exploit this vulnerability to submit special requests and execute arbitrary code in the application context
| VAR-202402-1428 | CVE-2023-43482 | TP-LINK Technologies of er7206 in the firmware OS Command injection vulnerability |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. TP-LINK Technologies of er7206 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK ER7206 is a multifunctional Gigabit router from China TP-LINK Company.
TP-LINK ER7206 1.3.0 build 20230322 Rel.70591 version has an operating system command injection vulnerability
| VAR-202402-1245 | CVE-2023-33069 | Classic buffer overflow vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
Memory corruption in Audio while processing the calibration data returned from ACDB loader. 9206 lte modem firmware, AQT1000 firmware, AR8035 Multiple Qualcomm products such as firmware have a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202402-1352 | CVE-2023-33068 | Classic buffer overflow vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
Memory corruption in Audio while processing IIR config data from AFE calibration block. 9206 lte modem firmware, AQT1000 firmware, AR8035 Multiple Qualcomm products such as firmware have a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202402-1418 | CVE-2023-33067 | Out-of-bounds write vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points. 9206 lte modem firmware, AQT1000 firmware, AR8035 Several Qualcomm products, such as firmware, contain an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202402-1427 | CVE-2023-33065 | Out-of-bounds read vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
Information disclosure in Audio while accessing AVCS services from ADSP payload. AQT1000 firmware, AR8035 firmware, c-v2x 9150 Multiple Qualcomm products, such as firmware, contain an out-of-bounds read vulnerability.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202402-1471 | CVE-2023-33064 | Out-of-bounds read vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Transient DOS in Audio when invoking callback function of ASM driver. AQT1000 firmware, AR8035 firmware, c-v2x 9150 Multiple Qualcomm products, such as firmware, contain an out-of-bounds read vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202402-1457 | CVE-2024-20825 | Samsung's Galaxy Store Vulnerability in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent. Samsung's Galaxy Store Exists in unspecified vulnerabilities.Information may be obtained