VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202309-2854 No CVE China Mobile Communications Co., Ltd. Smart Home Gateway H2-3 has a command execution vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
China Mobile Smart Home Gateway H2-3 is a general gateway device of China Mobile Communications. China Mobile Communications Co., Ltd.'s smart home gateway H2-3 has a command execution vulnerability. An attacker can use the vulnerability to gain server control permissions.
VAR-202309-2067 CVE-2023-37459 CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when a packet is received, the Contiki-NG network stack attempts to start the periodic TCP timer if it is a TCP packet with the SYN flag set. But the implementation does not first verify that a full TCP header has been received. Specifically, the implementation attempts to access the flags field from the TCP buffer in the following conditional expression in the `check_for_tcp_syn` function. For this reason, an attacker can inject a truncated TCP packet, which will lead to an out-of-bound read from the packet buffer. As of time of publication, a patched version is not available. As a workaround, one can apply the changes in Contiki-NG pull request #2510 to patch the system.
VAR-202309-2398 CVE-2023-37281 CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
Contiki-NG is an operating system for internet-of-things devices. In versions 4.9 and prior, when processing the various IPv6 header fields during IPHC header decompression, Contiki-NG confirms the received packet buffer contains enough data as needed for that field. But no similar check is done before decompressing the IPv6 address. Therefore, up to 16 bytes can be read out of bounds on the line with the statement `memcpy(&ipaddr->u8[16 - postcount], iphc_ptr, postcount);`. The value of `postcount` depends on the address compression used in the received packet and can be controlled by the attacker. As a result, an attacker can inject a packet that causes an out-of-bound read. As of time of publication, a patched version is not available. As a workaround, one can apply the changes in Contiki-NG pull request #2509 to patch the system.
VAR-202309-2800 No CVE Applied Electro Magnetics Private Limited CPE4600AA has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
CPE4600AA is a routing device. Applied Electro Magnetics Private Limited CPE4600AA has a weak password vulnerability. An attacker can use the vulnerability to gain WEB system permissions.
VAR-202309-0738 CVE-2023-38891 CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
VAR-202309-2235 CVE-2023-39285 CVSS V2: -
CVSS V3: 4.3
Severity: MEDIUM
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.
VAR-202309-0631 CVE-2023-38557 Siemens'  Spectrum Power 7  Vulnerability in improper permission assignment for critical resources in CVSS V2: 6.8
CVSS V3: 7.8
Severity: HIGH
A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges. Siemens' Spectrum Power 7 Contains a vulnerability in improper permission assignment for critical resources.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Spectrum Power 7 provides basic components for SCADA, communications and data modeling for control and monitoring systems. Suites of applications can be added to optimize network and generation management in all areas of energy management
VAR-202309-2837 No CVE There is a command execution vulnerability in the MPSec MSG4000 security gateway of Maipu Telecom Technology Co., Ltd. CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
MPSec MSG4000 is a security gateway product of Maipu Communication Technology Co., Ltd. There is a command execution vulnerability in the MPSec MSG4000 security gateway of Maipu Communication Technology Co., Ltd. An attacker can use the vulnerability to obtain server permissions.
VAR-202309-2820 No CVE There is an information leakage vulnerability in the load balancing system of Beijing Tianrongxin Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Tianrongxin load balancing system can provide users with a complete set of data center solutions, including link load balancing and server load balancing in a single data center, as well as global load balancing in multiple data centers. There is an information leakage vulnerability in the load balancing system of Beijing Tianrongxin Technology Co., Ltd. An attacker can use the vulnerability to obtain sensitive information.
VAR-202309-2842 No CVE New H3C Technology Co., Ltd. GR-1200W has a binary vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
The GR-1200W router is a wireless enterprise-level routing device produced by H3C Technology Co., Ltd. (H3C). There is a binary vulnerability in the GR-1200W of H3C Technology Co., Ltd., which can be used by attackers to gain server permissions.
VAR-202309-0621 CVE-2023-38558 Siemens SIMATIC PCS neo (Administration Console) information leakage vulnerability CVSS V2: 4.6
CVSS V3: 5.5
Severity: MEDIUM
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems
VAR-202309-0672 CVE-2023-3935 Wibu-Systems AG  of  CodeMeter Runtime  Out-of-bounds write vulnerability in products from multiple vendors such as CVSS V2: 7.6
CVSS V3: 9.8
Severity: CRITICAL
A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. Wibu-Systems AG of CodeMeter Runtime Products from multiple vendors, such as the following, contain out-of-bounds write vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. PSS(R)CAPE is a transmission and distribution network protection simulation software. PSS(R)E is a power system simulation and analysis tool for transmission operation and planning. PSS(R)ODMS is a CIM-based network model management tool with network analysis capabilities for planning and operational planning of transmission utilities. SIMATIC PCS neo is a distributed control system (DCS). SIMATIC WinCC Open Architecture (OA) is part of the SIMATIC HMI family. It is designed for applications requiring a high degree of customer-specific adaptability, large or complex applications, and projects that impose specific system requirements or functionality. SIMIT Simulation Platform allows simulating factory settings to predict failures at an early planning stage. SINEC INS (Infrastructure Network Services) is a web-based application that combines various network services in one tool. SINEMA Remote Connect is a management platform for remote networks that allows simple management of tunnel connections (VPN) between headquarters, service technicians and installed machines or plants. Siemens Industrial product WIBU system CodeMeter has a heap buffer overflow vulnerability, which is caused by failure to perform correct boundary checks. An attacker could exploit this vulnerability to cause a buffer overflow and execute arbitrary code on the system
VAR-202309-0673 CVE-2023-4701 CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
A Improper Privilege Management vulnerability through an incorrect use of privileged APIs in CodeMeter Runtime versions prior to 7.60c allow a local, low privileged attacker to use an API call for escalation of privileges in order gain full admin access on the host system
VAR-202309-2870 No CVE Ruijie Networks Co., Ltd. RG-NBR1600G has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
RG-NBR1600G is a Gigabit router product specially designed for Internet cafes and enterprise users. Ruijie Networks Co., Ltd.'s RG-NBR1600G has an unauthorized access vulnerability that allows an attacker to obtain sensitive information.
VAR-202309-2879 No CVE Maipu Telecom Technology Co., Ltd. MPSec ISG1000 security gateway has an information leakage vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
MPSec ISG1000 is a security gateway product of Maipu Communication Technology Co., Ltd. Maipu Telecom Technology Co., Ltd.'s MPSec ISG1000 security gateway has an information leakage vulnerability that allows attackers to exploit the vulnerability to obtain sensitive information.
VAR-202309-2171 CVE-2023-2071 Rockwell Automation PanelView Plus Code Issue Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function. Rockwell Automation PanelView Plus is a human-machine interface (HMI) product line from Rockwell Automation. These HMI devices are designed to integrate with industrial automation systems to provide operators with an intuitive interface to control and monitor production processes. PanelView Plus has a wide range of applications, especially in manufacturing, industrial control, and process control
VAR-202309-2231 CVE-2023-39637 CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.
VAR-202309-1960 CVE-2023-41367 CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
VAR-202309-0636 CVE-2023-28831 Integer overflow vulnerability in multiple Siemens products CVSS V2: 7.8
CVSS V3: 7.5
Severity: High
The OPC UA implementations (ANSI C and C++) in affected products contain an integer overflow vulnerability that could cause the application to run into an infinite loop during certificate validation. This could allow an unauthenticated remote attacker to create a denial of service condition by sending a specially crafted certificate. simatic cloud connect 7 cc712 firmware, simatic cloud connect 7 cc716 firmware, SIMATIC Drive Controller CPU 1504D TF Multiple Siemens products, including firmware, contain an integer overflow vulnerability.Service operation interruption (DoS) It may be in a state. SIMATIC Cloud Connect 7 is an IoT gateway for connecting programmable logic controllers to cloud services and allows field devices to interface with OPC UA servers as OPC UA clients. SIMATIC Drive Controllers are designed for the automation of production machines and combine the functions of the SIMATIC S7-1500 CPU and the SINAMICS S120 drive control. The SIMATIC ET 200SP Open Controller is a PC-based version of the SIMATIC S7-1500 controller and includes optional visualization combined with central I/O in a compact device. SIMATIC S7-1200 CPU products are designed for discrete and continuous control in industrial environments such as global manufacturing, food and beverage, and chemical industries. SIMATIC S7-1500 CPU products are designed for discrete and continuous control in industrial environments such as global manufacturing, food and beverage, and chemical industries. SIMATIC S7-1500 ODK CPUs offer the functionality of a standard S7-1500 CPU, but also offer the possibility to run C/C++ code within the CPU runtime to execute your own functions/algorithms implemented in C/C++. They are designed for discrete and continuous control in industrial environments such as the manufacturing, food and beverage, and chemical industries around the world. SIMATIC S7-1500 Software Controller is the SIMATIC software controller for PC-based automation solutions. SIMATIC S7-PLCSIM Advanced simulates S7-1200, S7-1500 and some other PLC derivatives. Includes full network access to simulated PLCs, even in virtualized environments. Siemens SIMATIC product ANSI C OPC UA SDK has a denial of service vulnerability
VAR-202309-0571 CVE-2023-41846 Siemens Tecnomatix Plant Simulation Buffer Overflow Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application is vulnerable to memory corruption while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process. Siemens Tecnomatix Plant Simulation is an industrial control equipment from Germany's Siemens Company. It uses discrete event simulation to conduct production volume analysis and optimization, thereby improving manufacturing system performance