VARIoT IoT vulnerabilities database
| VAR-202302-0082 | CVE-2023-22358 | BIG-IP Edge Client Windows Installer Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
In versions beginning with 7.2.2 to before 7.2.3.1, a DLL hijacking vulnerability exists in the BIG-IP Edge Client Windows Installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. (DoS) It may be in a state
| VAR-202302-0034 | CVE-2022-45098 | Dell PowerScale OneFS Vulnerability in plaintext storage of important information in |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure
| VAR-202302-0113 | CVE-2023-23555 | BIG-IP Virtual Edition and BIG-IP SPK Initialization vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
On BIG-IP Virtual Edition versions 15.1x beginning in 15.1.4 to before 15.1.8 and 14.1.x beginning in 14.1.5 to before 14.1.5.3, and BIG-IP SPK beginning in 1.5.0 to before 1.6.0, when FastL4 profile is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP Virtual Edition and BIG-IP SPK Has an initialization vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202302-0021 | CVE-2022-45102 | Dell EMC Data Protection Central Encoding and escaping vulnerabilities in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary \u2018Host\u2019 header values to poison a web cache or trigger redirections
| VAR-202302-0086 | CVE-2023-22574 | Dell PowerScale OneFS Vulnerability regarding information leakage from log files in |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A low-privileged user with permission to read logs on the cluster could potentially exploit this vulnerability, leading to Information disclosure and denial of service
| VAR-202302-0105 | CVE-2022-34398 | plural Dell In the product Time-of-check Time-of-use (TOCTOU) Race condition vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system. plural Dell The product has Time-of-check Time-of-use (TOCTOU) There is a race condition vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0125 | CVE-2022-45100 | Dell PowerScale OneFS Certificate validation vulnerabilities in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
Dell PowerScale OneFS, versions 8.2.x-9.3.x, contains an Improper Certificate Validation vulnerability. An remote unauthenticated attacker could potentially exploit this vulnerability, leading to a full compromise of the system. Dell PowerScale OneFS Exists in a certificate validation vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0068 | CVE-2022-45096 | Dell PowerScale OneFS Vulnerability in improperly limiting rendered user interface layers or frames in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An unauthenticated remote user could unintentionally lead an administrator to enable this vulnerability, leading to disclosure of information
| VAR-202302-0052 | CVE-2023-22572 | Dell PowerScale OneFS Vulnerability regarding information leakage from log files in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privilege local attacker could potentially exploit this vulnerability, leading to system takeover. (DoS) It may be in a state
| VAR-202302-0088 | CVE-2022-46756 | Dell VxRail Vulnerability in leaking resources to the wrong area in |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the container's underlying OS. Exploitation may lead to a system take over by an attacker. Dell VxRail Exists in a vulnerability related to the leakage of resources to the wrong area.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202302-0372 | CVE-2023-22340 | BIG-IP In NULL Pointer dereference vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
On BIG-IP versions 16.1.x before 16.1.3.3, 15.1.x before 15.1.8, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when a SIP profile is configured on a Message Routing type virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. BIG-IP for, NULL There is a vulnerability in pointer dereference.Service operation interruption (DoS) It may be in a state
| VAR-202301-2332 | CVE-2022-47035 | D-Link DIR-825 Classic buffer overflow vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint. D-Link DIR-825 Exists in a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. D-Link DIR-825 is a router made by China D-Link Company.
There is a buffer overflow vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and earlier versions. This vulnerability is caused by a boundary error when processing untrusted input
| VAR-202301-2429 | CVE-2022-48176 | plural Netgear Out-of-bounds write vulnerability in router products |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow. plural Netgear Router products contain an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202301-2353 | CVE-2023-22610 | Geo SCADA Vulnerabilities in the server |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of
Service against the Geo SCADA server when specific messages are sent to the server over the
database server TCP port. Geo SCADA An unspecified vulnerability exists in the server.Service operation interruption (DoS) It may be in a state. Affected Products: EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) (Versions prior to October 2022)
| VAR-202301-2352 | CVE-2023-22611 | plural EcoStruxure Geo SCADA Expert product ( old name ClearSCADA) Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specific messages are sent to the server over the database server TCP port. Affected Products: EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) (Versions prior to October 2022). EcoStruxure Geo SCADA Expert 2019 from 2021 ( old name ClearSCADA) Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202301-2015 | CVE-2022-2988 | SoMachine HVAC and EcoStruxure Machine Expert - HVAC Out-of-bounds write vulnerability in |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0). Schneider Electric SoMachine HVAC is a set of programming software dedicated to Schneider Electric logic controllers from Schneider Electric in France.
Schneider Electric SoMachine HVAC has a buffer overflow vulnerability, which can be exploited by remote attackers to submit special requests, resulting in the leakage of sensitive information
| VAR-202301-2263 | CVE-2022-40134 | plural Lenovo model's SMI Set BIOS Password WMI SMI Handler Out-of-bounds read vulnerability in |
CVSS V2: - CVSS V3: 4.4 Severity: MEDIUM |
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory
| VAR-202301-2211 | CVE-2022-38451 | FreshTomato Past traversal vulnerability in |
CVSS V2: - CVSS V3: 6.8 Severity: MEDIUM |
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. FreshTomato Exists in a past traversal vulnerability.Information may be obtained
| VAR-202301-1899 | CVE-2022-42484 | FreshTomato In OS Command injection vulnerability |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. (DoS) It may be in a state
| VAR-202301-2264 | CVE-2022-40136 | plural Lenovo Out-of-bounds read vulnerability in model |
CVSS V2: - CVSS V3: 4.4 Severity: MEDIUM |
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. plural Lenovo An out-of-bounds read vulnerability exists in the model.Information may be obtained