VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202302-0812 CVE-2022-34384 plural  Dell  Product permission management vulnerabilities CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. plural Dell The product contains a vulnerability in permission management.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202302-0830 CVE-2022-34387 Dell SupportAssist for Home PCs  and  SupportAssist for Business PCs  Vulnerability in leaking resources to the wrong area in CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. (DoS) It may be in a state
VAR-202302-0821 CVE-2023-0782 Shenzhen Tenda Technology Co.,Ltd.  of  ac23  Out-of-bounds write vulnerability in firmware CVSS V2: 8.3
CVSS V3: 7.2
Severity: HIGH
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640. Shenzhen Tenda Technology Co.,Ltd. of ac23 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda AC23 is a dual-band wireless router for home use launched by Tenda, designed for coverage in large homes and high-speed transmission. It supports 802.11acWave2 technology and has a maximum concurrent dual-band speed of 2033Mbps. Detailed vulnerability information is currently unavailable
VAR-202302-0637 CVE-2022-34389 Dell SupportAssist  Vulnerability in improperly limiting excessive authentication attempts in CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. Dell SupportAssist Is vulnerable to improper restrictions on excessive authentication attempts.Information may be obtained
VAR-202302-0696 CVE-2022-34392 SupportAssist for Home PCs  Session deadline vulnerability in CVSS V2: -
CVSS V3: 5.5
Severity: MEDIUM
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information
VAR-202302-0638 CVE-2022-46678 Wyse Management Suite  Vulnerability in CVSS V2: -
CVSS V3: 4.9
Severity: MEDIUM
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized
VAR-202302-0724 CVE-2022-34385 SupportAssist for Home PCs  and  SupportAssist for Business PCs  Cryptographic strength vulnerabilities in CVSS V2: -
CVSS V3: 5.5
Severity: MEDIUM
SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information
VAR-202302-0761 CVE-2022-34445 Dell PowerScale OneFS  Vulnerability regarding insufficient protection of authentication information in CVSS V2: -
CVSS V3: 6.0
Severity: MEDIUM
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. Dell PowerScale OneFS There are vulnerabilities in inadequate protection of credentials.Information may be obtained
VAR-202302-0636 CVE-2022-34386 Dell SupportAssist for Home PCs  and  SupportAssist for Business PCs  Vulnerability in using hard-coded credentials in CVSS V2: -
CVSS V3: 5.5
Severity: MEDIUM
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information
VAR-202302-0652 CVE-2023-24352 D-Link N300 WI-FI Router DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0738 CVE-2022-34366 Dell's  Dell SupportAssist for Home PCs  Improper Comparison Vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. Dell's Dell SupportAssist for Home PCs contains an improper comparison vulnerability.Information may be obtained
VAR-202302-0639 CVE-2023-24348 D-Link N300 WI-FI Router DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0786 CVE-2023-24349 D-Link N300 WI-FI Router DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0653 CVE-2023-24344 D-Link N300 WI-FI  router  DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0882 CVE-2023-24573 Dell Command | Monitor  Vulnerability in CVSS V2: -
CVSS V3: 7.1
Severity: HIGH
Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. Dell Command | Monitor Exists in unspecified vulnerabilities.Information is tampered with and service operation is interrupted (DoS) It may be in a state
VAR-202302-0739 CVE-2023-24345 D-Link N300 WI-FI  router  DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0704 CVE-2023-24350 D-Link N300 WI-FI Router DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0702 CVE-2023-24343 D-Link N300 WI-FI  router  DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0703 CVE-2023-24351 D-Link N300 WI-FI Router DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
VAR-202302-0815 CVE-2023-24347 D-Link N300 WI-FI  router  DIR-605L  Out-of-bounds write vulnerability in CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company. D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption