VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202211-0417 CVE-2022-44557 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality
VAR-202211-0418 CVE-2022-44560 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified
VAR-202211-0633 CVE-2022-44546 Huawei  of  HarmonyOS  and  EMUI  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. Huawei of HarmonyOS and EMUI Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202211-0676 CVE-2022-44548 Huawei  of  HarmonyOS  and  EMUI  Vulnerability regarding improper default permissions in CVSS V2: -
CVSS V3: 4.3
Severity: MEDIUM
There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing. Huawei of HarmonyOS and EMUI There is a vulnerability in improper default permissions.Information may be tampered with
VAR-202211-0397 CVE-2022-44559 Huawei HarmonyOS Code problem vulnerability CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation
VAR-202211-0384 CVE-2022-44552 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability
VAR-202211-0327 CVE-2022-44553 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically
VAR-202211-0419 CVE-2022-44555 Huawei HarmonyOS Security hole CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable
VAR-202211-0351 CVE-2022-20958 Cisco Systems  Cisco BroadWorks CommPilot Application Software  Server-side request forgery vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network. {{value}} ["%7b%7bvalue%7d%7d"])}]] . (DoS) It may be in a state
VAR-202211-0353 CVE-2022-20969 Cisco Systems  Cisco Umbrella  Cross-site scripting vulnerability in virtual appliances CVSS V2: -
CVSS V3: 4.8
Severity: MEDIUM
A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to the web application and persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information
VAR-202211-0399 CVE-2022-38660 HCL Technologies Limited  of  Domino server  Cross-site request forgery vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user. HCL Technologies Limited of Domino server Contains a cross-site request forgery vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202211-0385 CVE-2022-38654 HCL Technologies Limited  of  Domino server  Vulnerability in CVSS V2: -
CVSS V3: 5.5
Severity: MEDIUM
HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server to search the Domino directory will ignore xACL read restrictions. An authenticated attacker could leverage this vulnerability to access attributes from a user's person record. HCL Technologies Limited of Domino server Exists in unspecified vulnerabilities.Information may be obtained
VAR-202211-0095 CVE-2022-2969 Delta Industrial Automation DIALink Directory Traversal Arbitrary File Creation Vulnerability CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements within the pathname, which can cause the pathname to resolve to a location outside of the restricted directory. This vulnerability allows remote attackers to create arbitrary files on affected installations of Delta Industrial Automation DIALink. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.The specific flaw exists within the opcua endpoint of the web service, which listens on TCP port 5000 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of the web service. Delta Electronics Industrial Automation DIALink is an industrial automation IoT device from Delta Electronics, Taiwan, China
VAR-202211-0386 CVE-2022-20962 Cisco Systems  Cisco Identity Services Engine (ISE)  Past traversal vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to make unauthorized changes to the file system of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request with absolute path sequences. A successful exploit could allow the attacker to upload malicious files to arbitrary locations within the file system. Using this method, it is possible to access the underlying operating system and execute commands with system privileges. (DoS) It may be in a state
VAR-202211-0352 CVE-2022-20961 Cisco Systems  Cisco Identity Services Engine (ISE)  Cross-site request forgery vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions on the affected device with the privileges of the target user. (DoS) It may be in a state
VAR-202211-0485 CVE-2022-20956 Cisco Systems  Cisco Identity Services Engine (ISE)  Vulnerability in CVSS V2: -
CVSS V3: 8.8
Severity: HIGH
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-based management interface of an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to list, download, and delete certain files that they should not have access to. Cisco plans to release software updates that address this vulnerability. https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx ["https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-access-contol-EeufSUCx"] . (DoS) It may be in a state
VAR-202211-0677 CVE-2022-20951 Cisco Systems  Cisco BroadWorks Messaging Server  Server-side request forgery vulnerability in CVSS V2: -
CVSS V3: 6.5
Severity: MEDIUM
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web interface. A successful exploit could allow the attacker to obtain confidential information from the BroadWorks server and other device on the network. {{value}} ["%7b%7bvalue%7d%7d"])}]] . Cisco Systems Cisco BroadWorks Messaging Server Contains a server-side request forgery vulnerability.Information may be obtained
VAR-202211-0372 CVE-2022-20937 Cisco Systems  Cisco Identity Services Engine (ISE)  Resource exhaustion vulnerability in CVSS V2: -
CVSS V3: 5.3
Severity: MEDIUM
A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient management of system resources. An attacker could exploit this vulnerability by taking actions that cause Cisco ISE Software to receive specific RADIUS traffic. A successful and sustained exploit of this vulnerability could allow the attacker to cause reduced performance of the affected device, resulting in significant delays to RADIUS authentications. There are workarounds that address this vulnerability. Cisco Systems Cisco Identity Services Engine (ISE) Exists in a resource exhaustion vulnerability.Service operation interruption (DoS) It may be in a state
VAR-202211-0845 CVE-2022-20963 Cisco Systems  Cisco Identity Services Engine (ISE)  Cross-site scripting vulnerability in CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid credentials to access the web-based management interface of an affected device
VAR-202211-0164 CVE-2022-43106 Tenda AC23 Stack Overflow Vulnerability (CNVD-2023-15701) CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
Tenda AC23 V16.03.07.45_cn was discovered to contain a stack overflow via the schedStartTime parameter in the setSchedWifi function. Tenda AC23 is a dual-band Gigabit wireless router from China Tenda. An attacker could exploit this vulnerability to run arbitrary code in the context of an affected application