VARIoT IoT vulnerabilities database
| VAR-202304-2198 | CVE-2023-25495 | plural Lenovo Insufficient Protection of Credentials in Products Vulnerability |
CVSS V2: - CVSS V3: 4.9 Severity: MEDIUM |
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured. thinkagile hx5530 firmware, thinkagile hx7530 firmware, ThinkAgile VX3331 firmware etc. Lenovo The product contains an insufficient credential protection vulnerability.Information may be obtained
| VAR-202304-2186 | CVE-2023-2396 | NETGEAR SRX5308 Cross-site scripting vulnerability |
CVSS V2: 5.0 CVSS V3: 4.3 Severity: MEDIUM |
A vulnerability classified as problematic was found in Netgear SRX5308 up to 4.3.5-3. This vulnerability affects unknown code of the component Web Management Interface. The manipulation of the argument USERDBUsers.Password leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227674 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way
| VAR-202304-2228 | CVE-2023-2385 | of netgear SRX5308 Cross-site scripting vulnerability in firmware |
CVSS V2: 3.3 CVSS V3: 2.4 Severity: MEDIUM |
A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been rated as problematic. This issue affects some unknown processing of the file scgi-bin/platform.cgi?page=ike_policies.htm of the component Web Management Interface. The manipulation of the argument IpsecIKEPolicy.IKEPolicyName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227663. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. of netgear SRX5308 Firmware has a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202304-2200 | CVE-2023-2383 | of netgear SRX5308 Cross-site scripting vulnerability in firmware |
CVSS V2: 3.3 CVSS V3: 2.4 Severity: MEDIUM |
A vulnerability was found in Netgear SRX5308 up to 4.3.5-3. It has been classified as problematic. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.fromAddr leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227661 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. of netgear SRX5308 Firmware has a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202304-2278 | CVE-2023-2380 | NETGEAR SRX5308 Security hole |
CVSS V2: 6.8 CVSS V3: 6.5 Severity: MEDIUM |
A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. Affected is an unknown function. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-227658 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way
| VAR-202304-2264 | CVE-2023-2388 | of netgear SRX5308 Cross-site scripting vulnerability in firmware |
CVSS V2: 3.3 CVSS V3: 2.4 Severity: MEDIUM |
A vulnerability, which was classified as problematic, has been found in Netgear SRX5308 up to 4.3.5-3. Affected by this issue is some unknown functionality of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.fromAddr leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227666 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. of netgear SRX5308 Firmware has a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202304-2341 | CVE-2023-2389 | of netgear SRX5308 Cross-site scripting vulnerability in firmware |
CVSS V2: 3.3 CVSS V3: 2.4 Severity: MEDIUM |
A vulnerability, which was classified as problematic, was found in Netgear SRX5308 up to 4.3.5-3. This affects an unknown part of the file scgi-bin/platform.cgi?page=firewall_logs_email.htm of the component Web Management Interface. The manipulation of the argument smtpServer.emailServer leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227667. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. of netgear SRX5308 Firmware has a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202304-2122 | CVE-2023-29150 | mySCADA Technologies of myPRO In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. mySCADA Technologies of myPRO for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202304-2123 | CVE-2023-29169 | mySCADA Technologies of myPRO In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. mySCADA Technologies of myPRO for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202304-2125 | CVE-2023-28400 | mySCADA Technologies of myPRO In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. mySCADA Technologies of myPRO for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202304-2124 | CVE-2023-28384 | mySCADA Technologies of myPRO In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. mySCADA Technologies of myPRO for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202304-2121 | CVE-2023-28716 | mySCADA Technologies of myPRO In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. mySCADA Technologies of myPRO for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202304-2249 | CVE-2023-30546 | Contiki-NG Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Contiki-NG is an operating system for Internet of Things devices. An off-by-one error can be triggered in the Antelope database management system in the Contiki-NG operating system in versions 4.8 and prior. The problem exists in the Contiki File System (CFS) backend for the storage of data (file os/storage/antelope/storage-cfs.c). In the functions `storage_get_index` and `storage_put_index`, a buffer for merging two strings is allocated with one byte less than the maximum size of the merged strings, causing subsequent function calls to the cfs_open function to read from memory beyond the buffer size. The vulnerability has been patched in the "develop" branch of Contiki-NG, and is expected to be included in the next release. As a workaround, the problem can be fixed by applying the patch in Contiki-NG pull request #2425. Contiki-NG contains vulnerabilities related to out-of-bounds reads and vulnerabilities related to determining boundary conditions.Information may be obtained
| VAR-202304-2107 | CVE-2023-30280 | NETGEAR R6900 and NETGEAR R6700v3 Security hole |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Buffer Overflow vulnerability found in Netgear R6900 v.1.0.2.26, R6700v3 v.1.0.4.128, R6700 v.1.0.0.26 allows a remote attacker to execute arbitrary code and cause a denial ofservice via the getInputData parameter of the fwSchedule.cgi page
| VAR-202304-2390 | No CVE | Weak password vulnerability exists in TOTOLINK X5000R |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
TOTOLINK X5000R is a Gigabit dual-band WiFi6 router.
There is a weak password vulnerability in TOTOLINK X5000R, which can be exploited by attackers to obtain sensitive information.
| VAR-202304-1913 | CVE-2023-22916 | plural ZyXEL Product vulnerabilities |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
The configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FLEX 50(W) firmware versions 5.10 through 5.35, USG20(W)-VPN firmware versions 5.10 through 5.35, and VPN series firmware versions 5.00 through 5.35, which fails to properly sanitize user input. A remote unauthenticated attacker could leverage the vulnerability to modify device configuration data, resulting in DoS conditions on an affected device if the attacker could trick an authorized administrator to switch the management mode to the cloud mode. usg flex 100 firmware, usg flex 100w firmware, USG FLEX 200 firmware etc. ZyXEL There are unspecified vulnerabilities in the product.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202304-2073 | CVE-2023-28771 | Zyxel ZyWALL USG Operating system command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device
| VAR-202304-1973 | CVE-2023-22918 | plural ZyXEL Product vulnerabilities |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions 4.30 through 5.35, NWA110AX firmware version 6.50(ABTG.2) and earlier versions, WAC500 firmware version 6.50(ABVS.0) and earlier versions, and WAX510D firmware version 6.50(ABTF.2) and earlier versions, which could allow a remote authenticated attacker to retrieve encrypted information of the administrator on an affected device. ATP200 firmware, ATP100 firmware, ATP700 firmware etc. ZyXEL There are unspecified vulnerabilities in the product.Information may be obtained
| VAR-202304-1936 | CVE-2023-22917 | plural ZyXEL Classic buffer overflow vulnerability in the product |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firmware versions 5.00 through 5.32, USG FLEX 50(W) firmware versions 5.10 through 5.32, USG20(W)-VPN firmware versions 5.10 through 5.32, and VPN series firmware versions 5.00 through 5.35, which could allow a remote unauthenticated attacker to cause a core dump with a request error message on a vulnerable device by uploading a crafted configuration file. usg flex 100 firmware, usg flex 100w firmware, USG FLEX 200 firmware etc. ZyXEL The product contains a classic buffer overflow vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202304-2162 | CVE-2023-27991 | plural ZyXEL In the product OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely. ATP200 firmware, ATP100 firmware, ATP700 firmware etc. ZyXEL The product has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state