VARIoT IoT vulnerabilities database
| VAR-202307-2111 | CVE-2023-33743 | TeleAdapt RoomCast TA-2400 Privilege Escalation Vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available. The TeleAdapt RoomCast TA-2400 is an all-in-one, self-contained premium content streaming box for guest rooms from TeleAdapt UK. An attacker could exploit this vulnerability to gain elevated root privileges
| VAR-202307-2109 | CVE-2023-33745 | TeleAdapt RoomCast TA-2400 Privilege Escalation Vulnerability |
CVSS V2: 8.3 CVSS V3: 9.8 Severity: CRITICAL |
TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password). The TeleAdapt RoomCast TA-2400 is an all-in-one, self-contained premium content streaming box for guest rooms from TeleAdapt UK.
An escalation of privilege vulnerability exists in TeleAdapt RoomCast TA-2400, which is caused by improper permission management of Android Debug Bridge (ADB). An attacker could exploit this vulnerability to gain elevated root privileges
| VAR-202307-2352 | CVE-2023-2626 |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
There exists an authentication bypass vulnerability in OpenThread border router devices and implementations. This issue allows unauthenticated nodes to craft radio frames using “Key ID Mode 2”: a special mode using a static encryption key to bypass security checks, resulting in arbitrary IP packets being allowed on the Thread network.
This provides a pathway for an attacker to send/receive arbitrary IPv6 packets to devices on the LAN, potentially exploiting them if they lack additional authentication or contain any network vulnerabilities that would normally be mitigated by the home router’s NAT firewall. Effected devices have been mitigated through an automatic update beyond the affected range.
| VAR-202307-2464 | CVE-2023-21406 | Axis Communications Made A1001 Heap-based buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Ariel Harush and Roy Hodir from OTORIO have found a flaw in the AXIS A1001 when
communicating over OSDP. A heap-based buffer overflow was found in the pacsiod process which
is handling the OSDP communication allowing to write outside of the allocated buffer. By
appending invalid data to an OSDP message it was possible to write data beyond the heap
allocated buffer. The data written outside the buffer could be used to execute arbitrary code.
lease refer to the Axis security advisory for more information, mitigation and affected products and software versions. Axis Communications Provided by A1001 Network Door Controller The following vulnerabilities exist in. It was * by a third party on a neighboring network, Open Supervised Device Protocol (( OSDP ) adds invalid data to the message and executes arbitrary code
| VAR-202307-2405 | CVE-2023-21405 |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
Knud from Fraktal.fi has found a flaw in some Axis Network Door Controllers and Axis Network
Intercoms when communicating over OSDP, highlighting that the OSDP message parser crashes
the pacsiod process, causing a temporary unavailability of the door-controlling functionalities
meaning that doors cannot be opened or closed. No sensitive or customer data can be extracted
as the Axis device is not further compromised. Please refer to the Axis security advisory for more information, mitigation and affected products and software versions.
| VAR-202307-2026 | CVE-2023-3324 | ABB Abilit zenon Code problem vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
| VAR-202307-2025 | CVE-2023-3323 | ABB Abilit zenon Security hole |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
| VAR-202307-2024 | CVE-2023-3321 | ABB Abilit zenon Security hole |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
| VAR-202307-2149 | CVE-2023-3322 | ABB Abilit zenon Security hole |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted
programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.
This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.
| VAR-202307-2220 | No CVE | TOTOLINK T8 has a command execution vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
TOTOLINK T8 is a wireless dual-band router.
There is a command execution vulnerability in TOTOLINK T8, which can be exploited by attackers to gain control of the server.
| VAR-202307-1941 | CVE-2023-28728 | Panasonic Made Control FPWIN Pro7 Multiple vulnerabilities in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A stack-based buffer overflow in Panasonic Control FPWIN Pro versions 7.6.0.3 and all previous versions may allow arbitrary code execution when opening specially crafted project files. Panasonic Provided by Control FPWIN Pro7 contains multiple vulnerabilities: * Stack-based buffer overflow (CWE-121) - CVE-2023-28728 It was * Mistake of type (CWE-843) - CVE-2023-28729 It was * memory buffer error (CWE-119) - CVE-2023-28730 These vulnerability information are available at JPCERT/CC and reporting to product developers, After coordinating with product developers, for the purpose of dissemination to product users JVN It was announced at. Reporter : Michael Heinzl MrArbitrary code may be executed by tricking a user into reading a specially crafted file
| VAR-202307-1969 | CVE-2023-35087 | ASUS RT-AX56U Format string error vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by lacking validation for a specific value when calling cm_processChangedConfigMsg in ccm_processREQ_CHANGED_CONFIG function in AiMesh system. An unauthenticated remote attacker can exploit this vulnerability without privilege to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529
| VAR-202307-2004 | CVE-2023-35086 | ASUSTeK Computer Inc. of RT-AC86U firmware and RT-AX56U_V2 Format string vulnerability in firmware |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator privilege can exploit this vulnerability to perform remote arbitrary code execution, arbitrary system operation or disrupt service.
This issue affects RT-AX56U V2: 3.0.0.4.386_50460; RT-AC86U: 3.0.0.4_386_51529. ASUSTeK Computer Inc. of RT-AC86U firmware and RT-AX56U_V2 A format string vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202307-1790 | CVE-2023-20181 | Cisco Small Business SPA500 Series IP Phones Cross-Site Scripting Vulnerability |
CVSS V2: 6.4 CVSS V3: 6.1 Severity: MEDIUM |
A vulnerability in the web-based management interface of Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to conduct XSS attacks. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
For more information about these vulnerabilities, see the Details section of this advisory.
There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-web-multi-7kvPmu2F
| VAR-202307-1789 | CVE-2023-20218 | Cisco Small Business SPA500 Series IP Phones HTML Injection Vulnerability |
CVSS V2: 5.0 CVSS V3: 6.1 Severity: MEDIUM |
A vulnerability in web-based management interface of Cisco SPA500 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to to modify a web page in the context of a user's browser.
This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to alter the contents of a web page to redirect the user to potentially malicious websites, or the attacker could use this vulnerability to conduct further client-side attacks.
Cisco will not release software updates that address this vulnerability.
{{value}} ["%7b%7bvalue%7d%7d"])}]]. Cisco Small Business SPA500 Series IP Phones is a SPA500 series IP phone of Cisco (Cisco).
For more information about these vulnerabilities, see the Details section of this advisory.
There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-web-multi-7kvPmu2F
| VAR-202307-1699 | CVE-2023-30383 | plural TP-LINK Technologies Classic buffer overflow vulnerability in the product |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data
| VAR-202307-1849 | CVE-2023-30433 | IBM Security Verify Access Input validation error vulnerability |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 252186
| VAR-202307-1597 | CVE-2023-37758 | D-Link Systems, Inc. of DIR-815 Classic buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi. D-Link Systems, Inc. of DIR-815 Firmware has a classic buffer overflow vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202307-1521 | CVE-2023-35818 | plural Espressif Systems Product vulnerabilities |
CVSS V2: - CVSS V3: 6.8 Severity: MEDIUM |
An issue was discovered on Espressif ESP32 3.0 (ESP32_rev300 ROM) devices. An EMFI attack on ECO3 provides the attacker with a capability to influence the PC value at the CPU context level, regardless of Secure Boot and Flash Encryption status. By using this capability, the attacker can exploit another behavior in the chip to gain unauthorized access to the ROM download mode. Access to ROM download mode may be further exploited to read the encrypted flash content in cleartext format or execute stub code. esp32-d0wd-v3 firmware, esp32-d0wdr2-v3 firmware, esp32-u4wdh firmware etc. Espressif Systems There are unspecified vulnerabilities in the product.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202307-1561 | CVE-2023-37791 | D-Link Systems, Inc. of DIR-619L Out-of-bounds write vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link DIR-619L v2.04(TW) was discovered to contain a stack overflow via the curTime parameter at /goform/formLogin. D-Link Systems, Inc. of DIR-619L An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-619 is a series of routers produced by China D-Link Company.
D-Link DIR-619L v2.04(TW) version has a buffer overflow vulnerability. The vulnerability is caused by the fact that the curTime parameter of /goform/formLogin fails to correctly verify the length of the input data. Remote attackers can exploit this vulnerability on the system Execute arbitrary code or cause a denial of service attack