VARIoT IoT vulnerabilities database
| VAR-202302-0812 | CVE-2022-34384 | plural Dell Product permission management vulnerabilities |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. plural Dell The product contains a vulnerability in permission management.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0830 | CVE-2022-34387 | Dell SupportAssist for Home PCs and SupportAssist for Business PCs Vulnerability in leaking resources to the wrong area in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. (DoS) It may be in a state
| VAR-202302-0821 | CVE-2023-0782 | Shenzhen Tenda Technology Co.,Ltd. of ac23 Out-of-bounds write vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A vulnerability was found in Tenda AC23 16.03.07.45 and classified as critical. Affected by this issue is the function formSetSysToolDDNS/formGetSysToolDDNS of the file /bin/httpd. The manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220640. Shenzhen Tenda Technology Co.,Ltd. of ac23 An out-of-bounds write vulnerability exists in firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The Tenda AC23 is a dual-band wireless router for home use launched by Tenda, designed for coverage in large homes and high-speed transmission. It supports 802.11acWave2 technology and has a maximum concurrent dual-band speed of 2033Mbps. Detailed vulnerability information is currently unavailable
| VAR-202302-0637 | CVE-2022-34389 | Dell SupportAssist Vulnerability in improperly limiting excessive authentication attempts in |
CVSS V2: - CVSS V3: 5.3 Severity: MEDIUM |
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. Dell SupportAssist Is vulnerable to improper restrictions on excessive authentication attempts.Information may be obtained
| VAR-202302-0696 | CVE-2022-34392 | SupportAssist for Home PCs Session deadline vulnerability in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information
| VAR-202302-0638 | CVE-2022-46678 | Wyse Management Suite Vulnerability in |
CVSS V2: - CVSS V3: 4.9 Severity: MEDIUM |
Wyse Management Suite
3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized
| VAR-202302-0724 | CVE-2022-34385 | SupportAssist for Home PCs and SupportAssist for Business PCs Cryptographic strength vulnerabilities in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information
| VAR-202302-0761 | CVE-2022-34445 | Dell PowerScale OneFS Vulnerability regarding insufficient protection of authentication information in |
CVSS V2: - CVSS V3: 6.0 Severity: MEDIUM |
Dell PowerScale OneFS, versions 8.2.x through 9.3.x contain a weak encoding for a password. A malicious local privileged attacker may potentially exploit this vulnerability, leading to information disclosure. Dell PowerScale OneFS There are vulnerabilities in inadequate protection of credentials.Information may be obtained
| VAR-202302-0636 | CVE-2022-34386 | Dell SupportAssist for Home PCs and SupportAssist for Business PCs Vulnerability in using hard-coded credentials in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information
| VAR-202302-0652 | CVE-2023-24352 | D-Link N300 WI-FI Router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0738 | CVE-2022-34366 | Dell's Dell SupportAssist for Home PCs Improper Comparison Vulnerability in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. Dell's Dell SupportAssist for Home PCs contains an improper comparison vulnerability.Information may be obtained
| VAR-202302-0639 | CVE-2023-24348 | D-Link N300 WI-FI Router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0786 | CVE-2023-24349 | D-Link N300 WI-FI Router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0653 | CVE-2023-24344 | D-Link N300 WI-FI router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0882 | CVE-2023-24573 | Dell Command | Monitor Vulnerability in |
CVSS V2: - CVSS V3: 7.1 Severity: HIGH |
Dell Command | Monitor versions prior to 10.9 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. Dell Command | Monitor Exists in unspecified vulnerabilities.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202302-0739 | CVE-2023-24345 | D-Link N300 WI-FI router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0704 | CVE-2023-24350 | D-Link N300 WI-FI Router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0702 | CVE-2023-24343 | D-Link N300 WI-FI router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0703 | CVE-2023-24351 | D-Link N300 WI-FI Router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin. D-Link N300 WI-FI Router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption
| VAR-202302-0815 | CVE-2023-24347 | D-Link N300 WI-FI router DIR-605L Out-of-bounds write vulnerability in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus. D-Link N300 WI-FI router DIR-605L Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-605L is a wireless router made by China D-Link Company.
D-Link DIR-605L has a buffer overflow vulnerability, which can be exploited by attackers to cause remote code execution or service interruption