VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202307-2111 CVE-2023-33743 TeleAdapt RoomCast TA-2400 Privilege Escalation Vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available. The TeleAdapt RoomCast TA-2400 is an all-in-one, self-contained premium content streaming box for guest rooms from TeleAdapt UK. An attacker could exploit this vulnerability to gain elevated root privileges
VAR-202307-2109 CVE-2023-33745 TeleAdapt RoomCast TA-2400 Privilege Escalation Vulnerability CVSS V2: 8.3
CVSS V3: 9.8
Severity: CRITICAL
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password). The TeleAdapt RoomCast TA-2400 is an all-in-one, self-contained premium content streaming box for guest rooms from TeleAdapt UK. An escalation of privilege vulnerability exists in TeleAdapt RoomCast TA-2400, which is caused by improper permission management of Android Debug Bridge (ADB). An attacker could exploit this vulnerability to gain elevated root privileges
VAR-202307-2352 CVE-2023-2626 CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on the Thread network. This provides a pathway for an attacker to send/receive arbitrary IPv6 packets to devices on the LAN, potentially exploiting them if they lack additional authentication or contain any network vulnerabilities that would normally be mitigated by the home router’s NAT firewall. Effected devices have been mitigated through an automatic update beyond the affected range.
VAR-202307-2464 CVE-2023-21406 Axis Communications  Made  A1001  Heap-based buffer overflow vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which is handling the OSDP communication allowing to write outside of the allocated buffer. By appending invalid data to an OSDP message it was possible to write data beyond the heap allocated buffer. The data written outside the buffer could be used to execute arbitrary code.   lease refer to the Axis security advisory for more information, mitigation and affected products and software versions. Axis Communications Provided by A1001 Network Door Controller The following vulnerabilities exist in. It was * by a third party on a neighboring network, Open Supervised Device Protocol (( OSDP ) adds invalid data to the message and executes arbitrary code
VAR-202307-2405 CVE-2023-21405 CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes the pacsiod process, causing a temporary unavailability of the door-controlling functionalities meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.
VAR-202307-2026 CVE-2023-3324 ABB Abilit zenon Code problem vulnerability CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
VAR-202307-2025 CVE-2023-3323 ABB Abilit zenon Security hole CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
VAR-202307-2024 CVE-2023-3321 ABB Abilit zenon Security hole CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
VAR-202307-2149 CVE-2023-3322 ABB Abilit zenon Security hole CVSS V2: -
CVSS V3: 8.1
Severity: HIGH
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
VAR-202307-2220 No CVE TOTOLINK T8 has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
TOTOLINK T8 is a wireless dual-band router. There is a command execution vulnerability in TOTOLINK T8, which can be exploited by attackers to gain control of the server.
VAR-202307-1941 CVE-2023-28728 Panasonic  Made  Control FPWIN Pro7  Multiple vulnerabilities in CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files. Panasonic Provided by Control FPWIN Pro7 contains multiple vulnerabilities: * Stack-based buffer overflow (CWE-121) - CVE-2023-28728 It was * Mistake of type (CWE-843) - CVE-2023-28729 It was * memory buffer error (CWE-119) - CVE-2023-28730 These vulnerability information are available at JPCERT/CC and reporting to product developers, After coordinating with product developers, for the purpose of dissemination to product users JVN It was announced at. Reporter : Michael Heinzl MrArbitrary code may be executed by tricking a user into reading a specially crafted file
VAR-202307-1969 CVE-2023-35087 ASUS RT-AX56U Format string error vulnerability CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529
VAR-202307-2004 CVE-2023-35086 ASUSTeK Computer Inc.  of  RT-AC86U  firmware and  RT-AX56U_V2  Format string vulnerability in firmware CVSS V2: -
CVSS V3: 7.2
Severity: HIGH
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service. This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529. ASUSTeK Computer Inc. of RT-AC86U firmware and RT-AX56U_V2 A format string vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202307-1790 CVE-2023-20181 Cisco Small Business SPA500 Series IP Phones Cross-Site Scripting Vulnerability CVSS V2: 6.4
CVSS V3: 6.1
Severity: MEDIUM
A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. For more information about these vulnerabilities, see the Details section of this advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-web-multi-7kvPmu2F
VAR-202307-1789 CVE-2023-20218 Cisco Small Business SPA500 Series IP Phones HTML Injection Vulnerability CVSS V2: 5.0
CVSS V3: 6.1
Severity: MEDIUM
A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks. Cisco will not release software updates that address this vulnerability. {{value}} ["%7b%7bvalue%7d%7d"])}]]. Cisco Small Business SPA500 Series IP Phones is a SPA500 series IP phone of Cisco (Cisco). For more information about these vulnerabilities, see the Details section of this advisory. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-web-multi-7kvPmu2F
VAR-202307-1699 CVE-2023-30383 plural  TP-LINK Technologies  Classic buffer overflow vulnerability in the product CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data
VAR-202307-1849 CVE-2023-30433 IBM Security Verify Access Input validation error vulnerability CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 252186
VAR-202307-1597 CVE-2023-37758 D-Link Systems, Inc.  of  DIR-815  Classic buffer overflow vulnerability in firmware CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi. D-Link Systems, Inc. of DIR-815 Firmware has a classic buffer overflow vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202307-1521 CVE-2023-35818 plural  Espressif Systems  Product vulnerabilities CVSS V2: -
CVSS V3: 6.8
Severity: MEDIUM
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the chip to gain unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code. esp32-d0wd-v3 firmware, esp32-d0wdr2-v3 firmware, esp32-u4wdh firmware etc. Espressif Systems There are unspecified vulnerabilities in the product.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202307-1561 CVE-2023-37791 D-Link Systems, Inc.  of  DIR-619L  Out-of-bounds write vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin. D-Link Systems, Inc. of DIR-619L An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-619 is a series of routers produced by China D-Link Company. D-Link DIR-619L v2.04(TW) version has a buffer overflow vulnerability. The vulnerability is caused by the fact that the curTime parameter of /goform/formLogin fails to correctly verify the length of the input data. Remote attackers can exploit this vulnerability on the system Execute arbitrary code or cause a denial of service attack