VARIoT IoT vulnerabilities database
| VAR-202302-1322 | CVE-2022-34843 | Intel's Intel Trace Analyzer and Collector Integer overflow vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access. (DoS) It may be in a state
| VAR-202302-1269 | CVE-2022-38375 | fortinet's FortiNAC and FortiNAC-F Vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. fortinet's FortiNAC and FortiNAC-F Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1378 | CVE-2022-33869 | fortinet's FortiWan In OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands. fortinet's FortiWan for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Fortinet FortiWAN is a network device developed by Fortinet for performing load balancing and fault tolerance between different networks
| VAR-202302-1463 | CVE-2022-27482 | fortinet's FortiADC In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 through 6.2.2, 6.1.0 through 6.1.6, 6.0.x, 5.x.x allows attacker to execute arbitrary shell code as `root` via CLI commands. fortinet's FortiADC for, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1564 | CVE-2022-41334 | fortinet's FortiOS Cross-site scripting vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of the URL seen when the "Sign in with FortiCloud" button is clicked. fortinet's FortiOS Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202302-1400 | CVE-2022-43969 | Vulnerabilities in multiple Ricoh products |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials. RICOH MP C307 firmware, mp c407 firmware, mp c406 Unspecified vulnerabilities exist in multiple Ricoh products, including firmware.Information may be obtained and information may be tampered with
| VAR-202302-1205 | CVE-2022-34841 | Intel's media software development kit Buffer error vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Improper buffer restrictions in the Intel(R) Media SDK software before version 22.2.2 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's media software development kit Exists in a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1572 | CVE-2022-30306 | fortinet's Fortiweb Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted password. fortinet's Fortiweb Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1331 | CVE-2023-24238 | TOTOLINK of A7100RU Command injection vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules. TOTOLINK of A7100RU Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1358 | CVE-2022-36348 | Intel (R) SPS Firmware vulnerabilities |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Active debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel (R) SPS There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1471 | CVE-2022-33892 | Intel's Quartus Prime Past traversal vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's Quartus Prime Exists in a past traversal vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1271 | CVE-2022-39952 | fortinet's FortiNAC Vulnerability in leaking resources to the wrong area in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request. fortinet's FortiNAC Exists in a vulnerability related to the leakage of resources to the wrong area.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1559 | CVE-2023-23780 | fortinet's Fortiweb Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4 all versions allows attacker to escalation of privilege via specifically crafted HTTP requests. fortinet's Fortiweb Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1470 | CVE-2022-32570 | Intel's Quartus Prime Authentication vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's Quartus Prime There is an authentication vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1519 | CVE-2022-26062 | Intel's Intel Trace Analyzer and Collector Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 7.3 Severity: HIGH |
Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access. (DoS) It may be in a state
| VAR-202302-1376 | CVE-2022-26115 | fortinet's FortiSandbox Vulnerability related to the use of insufficiently strong password hashes in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access to the password database to efficiently mount bulk guessing attacks to recover the passwords. fortinet's FortiSandbox contains a vulnerability related to the use of insufficiently strong password hashes.Information may be obtained
| VAR-202302-1567 | CVE-2022-33946 | Intel's system usage report Authentication vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's system usage report There is an authentication vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1332 | CVE-2023-24236 | TOTOLINK of A7100RU Command injection vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules. TOTOLINK of A7100RU Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-1301 | CVE-2023-25653 | Cisco Systems Node.js for node-jose Infinite loop vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for web browsers and node.js-based servers. Prior to version 2.2.0, when using the non-default "fallback" crypto back-end, ECC operations in `node-jose` can trigger a Denial-of-Service (DoS) condition, due to a possible infinite loop in an internal calculation. For some ECC operations, this condition is triggered randomly; for others, it can be triggered by malicious input. The issue has been patched in version 2.2.0. Since this issue is only present in the "fallback" crypto implementation, it can be avoided by ensuring that either WebCrypto or the Node `crypto` module is available in the JS environment where `node-jose` is being run. Cisco Systems Node.js for node-jose Exists in an infinite loop vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202302-1275 | CVE-2022-26345 | Intel's openmp Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 7.3 Severity: HIGH |
Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's openmp Exists in a vulnerability in an element of an uncontrolled search path.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state