VARIoT IoT vulnerabilities database
| VAR-202302-0183 | CVE-2022-40693 | Moxa SDS-3008 series Industrial Ethernet Switch Vulnerability in plaintext transmission of important information in |
CVSS V2: 7.8 CVSS V3: 5.9 Severity: MEDIUM |
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability. Moxa SDS-3008 is a series of industrial switches produced by China Moxa (MOXA)
| VAR-202302-0131 | CVE-2022-46552 |
D-Link DIR-846 in the firmware OS Command injection vulnerability
Related entries in the VARIoT exploits database: VAR-E-202304-0282 |
CVSS V2: 10.0 CVSS V3: 8.8 Severity: HIGH |
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request. D-Link DIR-846 The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-846 is a wireless router made by China D-Link Company
| VAR-202302-0269 | CVE-2022-40691 | Moxa SDS-3008 series Industrial Ethernet Switch Vulnerability in |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability
| VAR-202302-0119 | CVE-2023-20073 | Unrestricted upload vulnerability of dangerous file types in multiple Cisco Systems products |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device. RV340 firmware, RV340W firmware, RV345 Multiple Cisco Systems products, including firmware, contain vulnerabilities that allow unrestricted upload of dangerous types of files.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The RV340, RV340W, RV345, and RV345P are Cisco's small business VPN routers.
There are binary vulnerabilities in many Cisco products, and attackers can use this vulnerability to upload files for overwriting.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-afu-EXxwA65V
| VAR-202302-0136 | CVE-2023-23110 | plural Netgear Vulnerability related to insufficient integrity verification of downloaded code in products |
CVSS V2: - CVSS V3: 7.4 Severity: HIGH |
An exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware image is ensured with a fixed checksum number. Therefore, an attacker can conduct a MITM attack to modify the user-uploaded firmware image and bypass the checksum verification. This affects WNR612v2 Wireless Routers 1.0.0.3 and earlier, DGN1000v3 Modem Router 1.0.0.22 and earlier, D6100 WiFi DSL Modem Routers 1.0.0.63 and earlier, WNR1000v2 Wireless Routers 1.1.2.60 and earlier, XAVN2001v2 Wireless-N Extenders 0.4.0.7 and earlier, WNR2200 Wireless Routers 1.0.1.102 and earlier, WNR2500 Wireless Routers 1.0.0.34 and earlier, R8900 Smart WiFi Routers 1.0.3.6 and earlier, and R9000 Smart WiFi Routers 1.0.3.6 and earlier. plural Netgear The product contains a flaw in the integrity verification of downloaded code.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202302-0073 | CVE-2023-23120 | TRENDnet TV-IP651WI Security hole |
CVSS V2: - CVSS V3: 5.9 Severity: MEDIUM |
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes TRENDnet TV-IP651WI Network Camera firmware version v1.07.01 and earlier vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification
| VAR-202302-0213 | CVE-2023-20076 | on multiple Cisco Systems products. OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execute arbitrary commands as root on the underlying host operating system. This vulnerability is due to incomplete sanitization of parameters that are passed in for activation of an application. An attacker could exploit this vulnerability by deploying and activating an application in the Cisco IOx application hosting environment with a crafted activation payload file. A successful exploit could allow the attacker to execute arbitrary commands as root on the underlying host operating system. Cisco IC3000 industrial computing gateway firmware, Cisco IOx , Cisco IOS XE Several Cisco Systems products include OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Cisco Iox is a secure development environment of Cisco (Cisco), which combines Cisco IOS and Linux OS for secure network connection and development of IOT applications.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-8whGn5dL
| VAR-202302-0098 | CVE-2023-0640 | TRENDnet TEW-652BRP Command injection vulnerability in |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown function of the file ping.ccp of the component Web Interface. The manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220020. TRENDnet TEW-652BRP Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TRENDnet TEW-811DRU is a wireless router produced by TRENDnet. Remote attackers can use this vulnerability to submit special requests and execute arbitrary commands
| VAR-202302-0321 | CVE-2023-0638 | TRENDnet TEW-811DRU Command Injection Vulnerability |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-220018 is the identifier assigned to this vulnerability. TRENDnet TEW-811DRU Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TRENDnet TEW-811DRU is a wireless router produced by TRENDnet. Attackers can use this vulnerability to submit special requests and execute arbitrary commands
| VAR-202302-0396 | CVE-2022-31364 | Cypress Bluetooth Mesh SDK Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 8.2 Severity: HIGH |
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is lower_transport_layer_on_seg. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered by sending a series of segmented packets with inconsistent SegN. (DoS) It may be in a state
| VAR-202302-0049 | CVE-2022-31363 | Cypress Bluetooth Mesh SDK Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 8.2 Severity: HIGH |
Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered during mesh provisioning. Because there is no check for mismatched SegN and TotalLength in Transaction Start PDU. (DoS) It may be in a state
| VAR-202302-0132 | CVE-2023-22281 | BIG-IP AFM Vulnerability in using uninitialized resources in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a BIG-IP AFM NAT policy with a destination NAT rule is configured on a FastL4 virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP AFM Exists in the use of uninitialized resources.Service operation interruption (DoS) It may be in a state
| VAR-202302-0048 | CVE-2023-0611 | TRENDnet TEW-652BRP Command injection vulnerability in |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01. This issue affects some unknown processing of the file get_set.ccp of the component Web Management Interface. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-219935. TRENDnet TEW-652BRP Contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0004 | CVE-2022-30904 | Bestechnic Bluetooth Mesh SDK Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 8.2 Severity: HIGH |
In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, because there is no check for the SegN field of the Transaction Start PDU. Bestechnic Bluetooth Mesh SDK (BES2300) Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0010 | CVE-2023-22418 | BIG-IP APM Open redirect vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious attacker to build an open redirect URI. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
| VAR-202302-0008 | CVE-2023-22283 | Windows for BIG-IP Edge Client Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
On versions beginning in 7.1.5 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client for Windows. User interaction and administrative privileges are required to exploit this vulnerability because the victim user needs to run the executable on the system and the attacker requires administrative privileges for modifying the files in the trusted search path. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. (DoS) It may be in a state
| VAR-202302-0009 | CVE-2023-22326 | BIG-IP and BIG-IQ Vulnerability in improper permission assignment for critical resources in |
CVSS V2: - CVSS V3: 4.9 Severity: MEDIUM |
In BIG-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, and all versions of BIG-IQ 8.x and 7.1.x, incorrect permission assignment vulnerabilities exist in the iControl REST and TMOS shell (tmsh) dig command which may allow an authenticated attacker with resource administrator or administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP and BIG-IQ Contains a vulnerability in improper permission assignment for critical resources.Information may be obtained
| VAR-202302-0372 | CVE-2023-22340 | BIG-IP In NULL Pointer dereference vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP for, NULL There is a vulnerability in pointer dereference.Service operation interruption (DoS) It may be in a state
| VAR-202302-0021 | CVE-2022-45102 | Dell EMC Data Protection Central Encoding and escaping vulnerabilities in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections
| VAR-202302-0030 | CVE-2023-23692 | Dell EMC DDOS In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. (DoS) It may be in a state