VARIoT IoT vulnerabilities database
| VAR-202302-1211 | CVE-2022-42735 | Apache Software Foundation of ShenYu Vulnerability in privilege management in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own.
This issue affects Apache ShenYu: 2.5.0.
Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/apache/shenyu/pull/3958 . Apache Software Foundation of ShenYu Exists in a permission management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Apache ShenYu is an asynchronous, high-performance, cross-language, and responsive API gateway of the Apache Foundation
| VAR-202302-1223 | CVE-2022-42455 | ASUSTeK Computer Inc. of armoury crate Vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and shipped with multiple ASUS software products, contains multiple IOCTL handlers that provide raw read and write access to port I/O and MSRs via unprivileged IOCTL calls. Local users can gain privileges. ASUSTeK Computer Inc. of armoury crate Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0672 | CVE-2023-22806 | ls-electric of xbc-dn32u Vulnerability in cleartext transmission of sensitive information in firmware |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This could allow an attacker to gain sensitive information such as user credentials. ls-electric of xbc-dn32u A vulnerability exists in the firmware regarding the transmission of sensitive information in plaintext.Information may be obtained. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea
| VAR-202302-1336 | CVE-2023-24498 | of netgear prosafe fs726tp Insufficient Credential Protection Vulnerability in Firmware |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
An uspecified endpoint in the web server of the switch does not properly authenticate the user identity, and may allow downloading a config page with the password to the switch in clear text. of netgear prosafe fs726tp A firmware vulnerability related to insufficient protection of credentials exists.Information may be obtained. NETGEAR ProSAFE FS726TP is a smart switch.
NETGEAR ProSAFE FS726TP has a security vulnerability. Attackers can exploit this vulnerability to obtain sensitive information
| VAR-202302-0669 | CVE-2023-0102 | ls-electric of xbc-dn32u Vulnerability related to lack of authentication for critical functions in firmware |
CVSS V2: 9.4 CVSS V3: 9.1 Severity: CRITICAL |
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files. ls-electric of xbc-dn32u Firmware has a lack of authentication vulnerability for critical functionality.Information is tampered with and service operation is interrupted (DoS) It may be in a state. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea. This vulnerability is due to the lack of authentication of the delete command
| VAR-202302-0668 | CVE-2023-22804 | ls-electric of xbc-dn32u Vulnerability related to lack of authentication for critical functions in firmware |
CVSS V2: 9.4 CVSS V3: 9.8 Severity: CRITICAL |
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device. ls-electric of xbc-dn32u Firmware has a lack of authentication vulnerability for critical functionality.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea
| VAR-202302-0667 | CVE-2023-22803 | ls-electric of xbc-dn32u Vulnerability related to lack of authentication for critical functions in firmware |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode arbitrarily. ls-electric of xbc-dn32u Firmware has a lack of authentication vulnerability for critical functionality.Information may be tampered with. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea
| VAR-202302-0671 | CVE-2023-22807 | ls-electric of xbc-dn32u Firmware vulnerabilities |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol. ls-electric of xbc-dn32u There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea
| VAR-202302-0670 | CVE-2023-22805 | LS ELECTRIC XBC-DN32U Access Control Error Vulnerability |
CVSS V2: 4.0 CVSS V3: 4.3 Severity: MEDIUM |
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device. ls-electric of xbc-dn32u There are unspecified vulnerabilities in the firmware.Service operation interruption (DoS) It may be in a state. LS ELECTRIC XBC-DN32U is a PLC programmable logic controller produced by LS ELECTRIC in Korea
| VAR-202302-1454 | CVE-2023-21777 | Azure Stack Hub Elevated Privileges in |
CVSS V2: - CVSS V3: 8.7 Severity: HIGH |
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
| VAR-202302-0946 | CVE-2023-24978 | Siemens' Tecnomatix Plant Simulation Vulnerability in accessing uninitialized pointers in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-19788). Siemens' Tecnomatix Plant Simulation Exists in an uninitialized pointer access vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of SPP files. The issue results from the lack of proper initialization of a pointer prior to accessing it
| VAR-202302-0945 | CVE-2023-24987 | Siemens' Tecnomatix Plant Simulation Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19809). Siemens' Tecnomatix Plant Simulation Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of SPP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure
| VAR-202302-0944 | CVE-2023-24993 | Siemens' Tecnomatix Plant Simulation Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19815). Siemens' Tecnomatix Plant Simulation Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of SPP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure
| VAR-202302-1035 | CVE-2023-21703 | Azure Data Box Gateway and Azure Stack Edge Remote code execution vulnerability in |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
Azure Data Box Gateway Remote Code Execution Vulnerability
| VAR-202302-1246 | CVE-2023-23852 | SAP Solution Manager Cross-site scripting vulnerability in |
CVSS V2: 6.4 CVSS V3: 6.1 Severity: MEDIUM |
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. SAP Solution Manager is a system monitoring system of SAP, Germany, which can facilitate the monitoring of technology-related and application-related functions of enterprises. When the malicious data is viewed, sensitive information can be obtained or user sessions can be hijacked
| VAR-202302-1280 | CVE-2022-22564 | Vulnerabilities related to the use of cryptographic algorithms in multiple Dell products |
CVSS V2: - CVSS V3: 5.9 Severity: MEDIUM |
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information
| VAR-202302-1214 | CVE-2023-0655 | SonicWALL of email security Vulnerability regarding information leakage due to error messages in |
CVSS V2: - CVSS V3: 5.3 Severity: MEDIUM |
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses
| VAR-202302-0998 | CVE-2023-24482 | Siemens' COMOS Classic buffer overflow vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All versions < V10.4.0.0.31), COMOS V10.4.1.0 (All versions < V10.4.1.0.32), COMOS V10.4.2.0 (All versions < V10.4.2.0.25). Cache validation service in COMOS is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute arbitrary code on the target system or cause denial of service condition. Siemens' COMOS Exists in a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0930 | CVE-2023-24995 | Siemens' Tecnomatix Plant Simulation Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19817). Siemens' Tecnomatix Plant Simulation Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of SPP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure
| VAR-202302-0929 | CVE-2023-24990 | Siemens' Tecnomatix Plant Simulation Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19812). Siemens' Tecnomatix Plant Simulation Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of SPP files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure