VARIoT IoT vulnerabilities database
| VAR-202303-2049 | CVE-2023-27135 | TOTOLINK of A7100RU Command injection vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg. TOTOLINK of A7100RU Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK A7100RU is a wireless router produced by TOTOLINK in China. in constructing commands. An attacker could exploit this vulnerability to execute arbitrary commands on the system
| VAR-202303-1767 | CVE-2023-27079 | Tenda G103 Command Injection Vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package. Tenda G103 is an enterprise-level Ap router from China Tenda Company
| VAR-202303-1729 | CVE-2023-28433 | Minio Inc. of Minio Vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which allows for arbitrary object placement across buckets. As a result, a user with low privileges, such as an access key, service account, or STS credential, which only has permission to `PutObject` in a specific bucket, can create an admin user. This issue is patched in RELEASE.2023-03-20T20-16-18Z. There are no known workarounds. Minio Inc. of Minio Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202303-1848 | CVE-2023-28434 | Minio Inc. of Minio Vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Minio is a Multi-Cloud Object Storage framework. Prior to RELEASE.2023-03-20T20-16-18Z, an attacker can use crafted requests to bypass metadata bucket name checking and put an object into any bucket while processing `PostPolicyBucket`. To carry out this attack, the attacker requires credentials with `arn:aws:s3:::*` permission, as well as enabled Console API access. This issue has been patched in RELEASE.2023-03-20T20-16-18Z. As a workaround, enable browser API access and turn off `MINIO_BROWSER=off`. Minio Inc. of Minio Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202303-1844 | CVE-2023-28432 | Minio Inc. of Minio Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Minio is a Multi-Cloud Object Storage framework. In a cluster deployment starting with RELEASE.2019-12-17T23-16-33Z and prior to RELEASE.2023-03-20T20-16-18Z, MinIO returns all environment variables, including `MINIO_SECRET_KEY`
and `MINIO_ROOT_PASSWORD`, resulting in information disclosure. All users of distributed deployment are impacted. All users are advised to upgrade to RELEASE.2023-03-20T20-16-18Z. Minio Inc. of Minio Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202303-1655 | CVE-2022-38452 | of netgear RBS750 Vulnerabilities related to private functions in firmware |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A command execution vulnerability exists in the hidden telnet service functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. of netgear RBS750 The firmware contains a vulnerability related to an undisclosed function.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. NETGEAR RBR750 is a home WiFi system from NETGEAR.
NETGEAR RBR750 version 4.6.8.5 has a command injection vulnerability
| VAR-202303-1595 | CVE-2022-37337 | of netgear RBS750 in the firmware OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. of netgear RBS750 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. NETGEAR RBR750 is a home WiFi system from NETGEAR. The vulnerability comes from the fact that the dev_name parameter fails to properly filter special characters, commands, etc. for constructing commands
| VAR-202303-1567 | CVE-2022-38458 | of netgear RBS750 Vulnerability related to lack of encryption of critical data in firmware |
CVSS V2: 5.4 CVSS V3: 5.9 Severity: MEDIUM |
A cleartext transmission vulnerability exists in the Remote Management functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. of netgear RBS750 Firmware has a vulnerability related to lack of encryption of critical data.Information may be obtained. NETGEAR RBR750 is a home WiFi system from NETGEAR
| VAR-202303-1641 | CVE-2022-36429 | of netgear RBS750 Vulnerabilities related to private functions in firmware |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability. of netgear RBS750 The firmware contains a vulnerability related to an undisclosed function.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. NETGEAR Orbi Satellite RBS750 is a professional-grade tri-band satellite router from NETGEAR
| VAR-202303-1622 | CVE-2022-43663 | WellinTech of KingHistorian Vulnerability regarding conversion error between numeric types in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
An integer conversion vulnerability exists in the SORBAx64.dll RecvPacket functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. WellinTech of KingHistorian Exists in a vulnerability related to conversion errors between numeric types.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202303-1661 | CVE-2022-45124 | WellinTech of KingHistorian Authentication vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
An information disclosure vulnerability exists in the User authentication functionality of WellinTech KingHistorian 35.01.00.05. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can sniff network traffic to leverage this vulnerability. WellinTech of KingHistorian There is an authentication vulnerability in.Information may be obtained
| VAR-202303-1599 | CVE-2023-27538 | Haxx of libcurl Authentication vulnerabilities in products from multiple vendors |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection. Haxx of libcurl Products from other vendors have authentication vulnerabilities.Information may be obtained. Description<!----> This CVE is under investigation by Red Hat Product Security. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202310-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: curl: Multiple Vulnerabilities
Date: October 11, 2023
Bugs: #887745, #894676, #902801, #906590, #910564, #914091, #915195
ID: 202310-12
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in curl, the worst of
which could result in arbitrary code execution.
Background
==========
A command line tool and library for transferring data with URLs.
Affected packages
=================
Package Vulnerable Unaffected
------------- ------------ ------------
net-misc/curl < 8.3.0-r2 >= 8.3.0-r2
Description
===========
Multiple vulnerabilities have been discovered in curl. Please review the
CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Note that the risk of remote code execution is limited to SOCKS usage.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All curl users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/curl-8.3.0-r2"
References
==========
[ 1 ] CVE-2022-43551
https://nvd.nist.gov/vuln/detail/CVE-2022-43551
[ 2 ] CVE-2022-43552
https://nvd.nist.gov/vuln/detail/CVE-2022-43552
[ 3 ] CVE-2023-23914
https://nvd.nist.gov/vuln/detail/CVE-2023-23914
[ 4 ] CVE-2023-23915
https://nvd.nist.gov/vuln/detail/CVE-2023-23915
[ 5 ] CVE-2023-23916
https://nvd.nist.gov/vuln/detail/CVE-2023-23916
[ 6 ] CVE-2023-27533
https://nvd.nist.gov/vuln/detail/CVE-2023-27533
[ 7 ] CVE-2023-27534
https://nvd.nist.gov/vuln/detail/CVE-2023-27534
[ 8 ] CVE-2023-27535
https://nvd.nist.gov/vuln/detail/CVE-2023-27535
[ 9 ] CVE-2023-27536
https://nvd.nist.gov/vuln/detail/CVE-2023-27536
[ 10 ] CVE-2023-27537
https://nvd.nist.gov/vuln/detail/CVE-2023-27537
[ 11 ] CVE-2023-27538
https://nvd.nist.gov/vuln/detail/CVE-2023-27538
[ 12 ] CVE-2023-28319
https://nvd.nist.gov/vuln/detail/CVE-2023-28319
[ 13 ] CVE-2023-28320
https://nvd.nist.gov/vuln/detail/CVE-2023-28320
[ 14 ] CVE-2023-28321
https://nvd.nist.gov/vuln/detail/CVE-2023-28321
[ 15 ] CVE-2023-28322
https://nvd.nist.gov/vuln/detail/CVE-2023-28322
[ 16 ] CVE-2023-32001
https://nvd.nist.gov/vuln/detail/CVE-2023-32001
[ 17 ] CVE-2023-38039
https://nvd.nist.gov/vuln/detail/CVE-2023-38039
[ 18 ] CVE-2023-38545
https://nvd.nist.gov/vuln/detail/CVE-2023-38545
[ 19 ] CVE-2023-38546
https://nvd.nist.gov/vuln/detail/CVE-2023-38546
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202310-12
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2023 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
. ==========================================================================
Ubuntu Security Notice USN-5964-1
March 20, 2023
curl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in curl.
Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries
Details:
Harry Sintonen discovered that curl incorrectly handled certain TELNET
connection options. Due to lack of proper input scrubbing, curl could pass
on user name and telnet options to the server as provided, contrary to
expectations. (CVE-2023-27533)
Harry Sintonen discovered that curl incorrectly handled special tilde
characters when used with SFTP paths. A remote attacker could possibly use
this issue to circumvent filtering. (CVE-2023-27534)
Harry Sintonen discovered that curl incorrectly reused certain FTP
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27535)
Harry Sintonen discovered that curl incorrectly reused connections when the
GSS delegation option had been changed. This could lead to the option being
reused, contrary to expectations. (CVE-2023-27536)
Harry Sintonen discovered that curl incorrectly reused certain SSH
connections. This could lead to the wrong credentials being reused,
contrary to expectations. (CVE-2023-27538)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
curl 7.85.0-1ubuntu0.5
libcurl3-gnutls 7.85.0-1ubuntu0.5
libcurl3-nss 7.85.0-1ubuntu0.5
libcurl4 7.85.0-1ubuntu0.5
Ubuntu 22.04 LTS:
curl 7.81.0-1ubuntu1.10
libcurl3-gnutls 7.81.0-1ubuntu1.10
libcurl3-nss 7.81.0-1ubuntu1.10
libcurl4 7.81.0-1ubuntu1.10
Ubuntu 20.04 LTS:
curl 7.68.0-1ubuntu2.18
libcurl3-gnutls 7.68.0-1ubuntu2.18
libcurl3-nss 7.68.0-1ubuntu2.18
libcurl4 7.68.0-1ubuntu2.18
Ubuntu 18.04 LTS:
curl 7.58.0-2ubuntu3.24
libcurl3-gnutls 7.58.0-2ubuntu3.24
libcurl3-nss 7.58.0-2ubuntu3.24
libcurl4 7.58.0-2ubuntu3.24
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5964-1
CVE-2023-27533, CVE-2023-27534, CVE-2023-27535, CVE-2023-27536,
CVE-2023-27538
Package Information:
https://launchpad.net/ubuntu/+source/curl/7.85.0-1ubuntu0.5
https://launchpad.net/ubuntu/+source/curl/7.81.0-1ubuntu1.10
https://launchpad.net/ubuntu/+source/curl/7.68.0-1ubuntu2.18
https://launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.24
| VAR-202303-1502 | CVE-2023-26806 | Shenzhen Tenda Technology Co.,Ltd. of W20E Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Tenda W20E v15.11.0.6(US_W20EV4.0br_v15.11.0.6(1068_1546_841 is vulnerable to Buffer Overflow via function formSetSysTime,. Shenzhen Tenda Technology Co.,Ltd. of W20E An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202303-1668 | CVE-2023-26805 | Shenzhen Tenda Technology Co.,Ltd. of W20E Out-of-bounds write vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Tenda W20E v15.11.0.6 (US_W20EV4.0br_v15.11.0.6(1068_1546_841)_CN_TDC) is vulnerable to Buffer Overflow via function formIPMacBindModify. Shenzhen Tenda Technology Co.,Ltd. of W20E An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202303-1689 | CVE-2023-28116 | Contiki-NG Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an out-of-bounds write can occur in the BLE L2CAP module of the Contiki-NG operating system. The network stack of Contiki-NG uses a global buffer (packetbuf) for processing of packets, with the size of PACKETBUF_SIZE. In particular, when using the BLE L2CAP module with the default configuration, the PACKETBUF_SIZE value becomes larger then the actual size of the packetbuf. When large packets are processed by the L2CAP module, a buffer overflow can therefore occur when copying the packet data to the packetbuf. The vulnerability has been patched in the "develop" branch of Contiki-NG, and will be included in release 4.9. The problem can be worked around by applying the patch manually. Contiki-NG Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state.
There is a security vulnerability in Contiki-NG 4.8 and earlier versions
| VAR-202303-1538 | CVE-2023-27977 | plural Schneider Electric Insufficient Validation of Data Trust in Products Vulnerability |
CVSS V2: 6.4 CVSS V3: 5.3 Severity: MEDIUM |
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior). This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Schneider Electric IGSS. Authentication is not required to exploit this vulnerability.The specific flaw exists within the IGSSdataServer process, which listens on TCP port 12401 by default. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to create a denial-of-service condition on the system
| VAR-202303-1424 | CVE-2023-27984 | Schneider Electric IGSS Data Server Input Validation Error Vulnerability |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior). Schneider Electric of custom reports , IGSS Dashboard (DashBoard.exe) , igss data server There is an input validation vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the openReport function. The issue results from the lack of proper input validation. An attacker can leverage this vulnerability to execute code in the context of the current user. Schneider Electric IGSS Data Server is a data server of an interactive graphic Scada system of French Schneider Electric (Schneider Electric)
| VAR-202303-1322 | CVE-2023-21455 | Samsung's exynos Firmware vulnerabilities |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message. Samsung's exynos There are unspecified vulnerabilities in the firmware.Information may be obtained and information may be tampered with
| VAR-202303-1376 | CVE-2023-21464 | Samsung's calendar Vulnerability in |
CVSS V2: - CVSS V3: 3.3 Severity: LOW |
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status. Samsung's calendar Exists in unspecified vulnerabilities.Information may be tampered with
| VAR-202303-1372 | CVE-2023-27978 | plural Schneider Electric Product untrusted data deserialization vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS Dashboard(DashBoard.exe)(V16.0.0.23040 and prior), Custom Reports(RMS16.dll)(V16.0.0.23040 and prior). Schneider Electric of custom reports , IGSS Dashboard (DashBoard.exe) , igss data server There is a vulnerability in deserialization of untrusted data.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric IGSS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the DashFiles class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the current user. Schneider Electric IGSS Data Server is a data server of an interactive graphic Scada system of French Schneider Electric (Schneider Electric)