VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202212-1032 CVE-2022-38379 fortinet's  FortiSOAR  Cross-site scripting vulnerability in CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR. fortinet's FortiSOAR Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
VAR-202212-0644 CVE-2022-38123 Secomea GateManager Input validation error vulnerability CVSS V2: -
CVSS V3: 7.2
Severity: HIGH
Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.
VAR-202212-0781 CVE-2022-33876 fortinet's  FortiADC  Input verification vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific extension from the underlying Linux system via crafted HTTP requests. fortinet's FortiADC There is an input validation vulnerability in.Information may be obtained
VAR-202212-2681 No CVE Weak password vulnerability exists in Infinova HD Network Mini Dome CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Infinova, founded in 1993, takes smart security as its core. It is a smart city, smart home solution provider and operation service provider, providing smart security, smart city, smart home, big data and Internet operation services for the world. Infinova HD Network Mini Dome has a weak password vulnerability. Attackers can log in to the system background through the default password to obtain sensitive information.
VAR-202212-0441 CVE-2022-25682 Buffer error vulnerability in multiple Qualcomm products CVSS V2: -
CVSS V3: 8.4
Severity: HIGH
Memory corruption in MODEM UIM due to usage of out of range pointer offset while decoding command from card in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. APQ8009 firmware, APQ8009W firmware, APQ8017 Multiple Qualcomm products such as firmware contain a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202212-0878 CVE-2022-43516 Microsoft's  Windows Firewall  Vulnerabilities in products from multiple vendors such as CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI). Microsoft's Windows Firewall Unspecified vulnerabilities exist in products from multiple vendors.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202212-0619 CVE-2022-20502 Google  of  Android  Vulnerability in using free memory in CVSS V2: 7.8
CVSS V3: 5.5
Severity: MEDIUM
In GetResolvedMethod of entrypoint_utils-inl.h, there is a possible use after free due to a stale cache. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222166527. Google of Android Exists in a vulnerability related to the use of freed memory.Information may be obtained. Google Pixel is a smartphone of Google (Google). A remote attacker could exploit this vulnerability to cause a denial of service (disk consumption and massive notifications) with a series of requests with malformed parameters
VAR-202212-2689 No CVE VH121-A2 of Shenzhen Infinitor Technology Co., Ltd. has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Infinova is the world's leading manufacturer of electronic security products and provider of industry solutions. VH121-A2 of Shenzhen Infinitor Technology Co., Ltd. has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202212-0542 CVE-2022-25695 Array index validation vulnerability in multiple Qualcomm products CVSS V2: -
CVSS V3: 8.4
Severity: HIGH
Memory corruption in MODEM due to Improper Validation of Array Index while processing GSTK Proactive commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. APQ8009 firmware, APQ8009W firmware, APQ8017 Multiple Qualcomm products, including firmware, contain vulnerabilities related to array index validation.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202212-0514 CVE-2022-42507 Google  of  Android  Out-of-bounds write vulnerability in CVSS V2: 6.5
CVSS V3: 6.7
Severity: MEDIUM
In ProtocolSimBuilder::BuildSimUpdatePb3gEntry of protocolsimbuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241388774References: N/A. Google of Android Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Google Pixel is a smart phone of Google (Google). Google Pixel has a buffer overflow vulnerability. An attacker can exploit this vulnerability to remotely execute arbitrary code
VAR-202212-0570 CVE-2022-42501 Google  of  Android  Out-of-bounds write vulnerability in CVSS V2: 6.5
CVSS V3: 6.7
Severity: MEDIUM
In HexString2Value of util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-241231403References: N/A. Google of Android Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Google Pixel is a smart phone of Google (Google). Google Pixel has a buffer overflow vulnerability. Attackers can use this vulnerability to execute unauthorized instructions, obtain system privileges, and then perform various illegal operations
VAR-202212-0688 CVE-2022-20608 Google  of  Android  Out-of-bounds read vulnerability in CVSS V2: 4.6
CVSS V3: 5.5
Severity: MEDIUM
In Pixel cellular firmware, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-239239246References: N/A. Google of Android Exists in an out-of-bounds read vulnerability.Information may be obtained. Google Pixel is a smart phone of Google (Google). Google Pixel has a buffer error vulnerability. A remote attacker could exploit this vulnerability to obtain sensitive information
VAR-202212-0486 CVE-2022-44039 Franklin Fueling System Colibri Security hole CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with the mode "wb" which allows overwriting file if exists. Overwriting files such as passwd, allows an attacker to escalate his privileges by planting backdoor user with root privilege or change root password
VAR-202212-0389 CVE-2022-45313 MikroTik RouterOS Buffer error vulnerability CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
Mikrotik RouterOs before stable v7.5 was discovered to contain an out-of-bounds read in the hotspot process. This vulnerability allows attackers to execute arbitrary code via a crafted nova message
VAR-202212-0790 CVE-2022-20535 Google  of  Android  Vulnerability regarding observable inconsistencies in CVSS V2: 1.7
CVSS V3: 3.3
Severity: LOW
In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-233605242. Google of Android Exists in observable mismatch vulnerabilities.Information may be obtained. Google Pixel is a smartphone made by the American company Google. Google Pixel has security flaw. An attacker can exploit this vulnerability to cause information leakage
VAR-202212-0421 CVE-2022-46327 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause privilege escalation, which results in system service exceptions
VAR-202212-0449 CVE-2021-46856 EMUI  and  HarmonyOS  Past traversal vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. EMUI and HarmonyOS Exists in a past traversal vulnerability.Information may be obtained
VAR-202212-0384 CVE-2022-46318 Huawei  of  HarmonyOS  and  EMUI  Vulnerability in CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
The HAware module has a function logic error. Successful exploitation of this vulnerability will affect the account removal function in Settings. Huawei of HarmonyOS and EMUI Exists in unspecified vulnerabilities.Information may be tampered with
VAR-202212-0422 CVE-2022-46310 Huawei  of  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The TelephonyProvider module has a vulnerability in obtaining values.Successful exploitation of this vulnerability may affect data confidentiality. Huawei of HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
VAR-202212-0385 CVE-2022-46321 Huawei  of  HarmonyOS  and  EMUI  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The Wi-Fi module has a vulnerability in permission verification. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of HarmonyOS and EMUI Exists in unspecified vulnerabilities.Information may be obtained