VARIoT IoT vulnerabilities database
| VAR-202210-1397 | CVE-2022-35884 | Abode Systems, Inc. of Abode iota All-In-One Security Kit Format string vulnerability in firmware |
CVSS V2: - CVSS V3: 8.2 Severity: HIGH |
Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `ssid_hex` HTTP parameter, as used within the `/action/wirelessConnect` handler. Abode Systems, Inc. of Abode iota All-In-One Security Kit A format string vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Abode Iota is a solid DIY home security system from Abode Corporation
| VAR-202210-1393 | CVE-2022-35879 | Abode Systems, Inc. of Abode iota All-In-One Security Kit Format string vulnerability in firmware |
CVSS V2: - CVSS V3: 7.1 Severity: HIGH |
Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `controlURL` XML tag, as used within the `DoUpdateUPnPbyService` action handler. Abode Systems, Inc. of Abode iota All-In-One Security Kit A format string vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Abode Iota is a solid DIY home security system from Abode Corporation
| VAR-202210-1392 | CVE-2022-35880 | Abode Systems, Inc. of Abode iota All-In-One Security Kit Format string vulnerability in firmware |
CVSS V2: - CVSS V3: 7.1 Severity: HIGH |
Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `NewInternalClient` XML tag, as used within the `DoUpdateUPnPbyService` action handler. Abode Systems, Inc. of Abode iota All-In-One Security Kit A format string vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Abode Iota is a solid DIY home security system from Abode Corporation
| VAR-202210-1817 | CVE-2022-41617 | F5 BIG-IP Command injection vulnerability |
CVSS V2: - CVSS V3: 7.2 Severity: HIGH |
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is provisioned, an authenticated remote code execution vulnerability exists in the BIG-IP iControl REST interface
| VAR-202210-1446 | CVE-2022-25750 | Double release vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 8.4 Severity: HIGH |
Memory corruption in BTHOST due to double free while music playback and calls over bluetooth headset in Snapdragon Mobile. kailua firmware, sg8275 firmware, sg8275p Multiple Qualcomm products, including firmware, contain a double release vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202210-1374 | CVE-2022-41832 | F5 BIG-IP Security hole |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource utilization
| VAR-202210-1306 | CVE-2022-41835 | F5 F5OS-A Security hole |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to execute limited set of commands in a container and impact the F5OS controller. F5 F5OS-A is an operating system software produced by F5 Corporation in the United States
| VAR-202210-1412 | CVE-2022-41833 | F5 BIG-IP Resource Management Error Vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5
| VAR-202210-1430 | CVE-2022-41983 | F5 BIG-IP Security hole |
CVSS V2: - CVSS V3: 3.7 Severity: LOW |
On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, while Intel QAT (QuickAssist Technology) and the AES-GCM/CCM cipher is in use, undisclosed conditions can cause BIG-IP to send data unencrypted even with an SSL Profile applied
| VAR-202210-1812 | CVE-2022-20955 | Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Path traversal vulnerability |
CVSS V2: - CVSS V3: 7.1 Severity: HIGH |
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
| VAR-202210-1426 | CVE-2022-41694 | F5 BIG-IP Input validation error vulnerability |
CVSS V2: - CVSS V3: 4.9 Severity: MEDIUM |
In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can cause MCPD to terminate. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5
| VAR-202210-1428 | CVE-2022-41813 | F5 BIG-IP Input validation error vulnerability |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5. The following versions are affected: 16.1.x versions prior to 16.1.3.1, 15.1.x versions prior to 15.1.6.1, 14.1.x versions prior to 14.1.5, all versions prior to 13.1.x
| VAR-202210-1443 | CVE-2022-20776 | Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Path traversal vulnerability |
CVSS V2: - CVSS V3: 6.7 Severity: MEDIUM |
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory
| VAR-202210-1641 | CVE-2022-20959 | Cisco Identity Services Engine Cross-site scripting vulnerability |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by persuading an authenticated administrator of the web-based management interface to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information
| VAR-202210-1372 | CVE-2022-41691 | F5 BIG-IP Advanced WAF/ASM Security hole |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. F5 BIG-IP Advanced WAF/ASM is a web application firewall developed by F5 Corporation in the United States
| VAR-202210-1704 | CVE-2022-36795 | F5 BIG-IP Security hole |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Auto Receive Window Enabled is configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5. There are security vulnerabilities in F5 BIG-IP versions 17.0.x to 17.0.0.1, 16.1.x to 16.1.3.1, 15.1.x to 15.1.7, 14.1.x to 14.1.5.1
| VAR-202210-1676 | CVE-2022-41836 | F5 BIG-IP Input validation error vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate
| VAR-202210-1707 | CVE-2022-43184 | D-Link DIR-878 Command injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
| VAR-202210-1307 | CVE-2022-41787 | F5 BIG-IP Code problem vulnerability |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can cause TMM to terminate. F5 BIG-IP is an application delivery platform integrated with network traffic management, application security management, load balancing and other functions of the US company F5. The following versions are affected: BIG-IP 17.0.x prior to 17.0.0.1, BIG-IP 16.1.x prior to 16.1.3.1, BIG-IP 15.1.x prior to 15.1.6.1, BIG-IP 14.1.5.1 Previous 14.1.x versions, BIG-IP 13.1.x versions prior to 13.1.5.1
| VAR-202210-1348 | CVE-2022-43026 | Tenda TX3 has an unknown vulnerability (CNVD-2022-70592) |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg. The Tenda TX3 is a wireless router from the Chinese company Tenda. No detailed vulnerability details are currently available