VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202209-0297 CVE-2022-27491 fortinet's  FortiOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim. fortinet's FortiOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202209-0268 CVE-2022-26114 fortinet's  FortiMail  Cross-site scripting vulnerability in CVSS V2: -
CVSS V3: 6.1
Severity: MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages. fortinet's FortiMail Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
VAR-202209-0337 CVE-2022-40109 TOTOLINK  of  A3002R  Improper default permissions vulnerability in firmware CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. TOTOLINK of A3002R A firmware vulnerability related to improper default permissions exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202209-0263 CVE-2022-26858 Authentication vulnerabilities in multiple Dell products CVSS V2: -
CVSS V3: 7.8
Severity: HIGH
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. Alienware m15 R6 firmware, ChengMing 3980 firmware, ChengMing 3988 Authentication vulnerabilities exist in multiple Dell products, including firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202209-0154 CVE-2022-37840 TOTOLINK  of  a860r  Classic buffer overflow vulnerability in firmware CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability. TOTOLINK of a860r Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The TOTOLINK A860R is a dual-band wireless router with a maximum transmission rate of 1200Mbps. It utilizes 6-antenna dual-band concurrent technology and supports remote management via a mobile app. It is suitable for small and medium-sized businesses and home network environments. No detailed vulnerability details are currently available
VAR-202209-0252 CVE-2022-29053 fortinet's  FortiOS  Vulnerability in CVSS V2: -
CVSS V3: 3.3
Severity: LOW
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it. fortinet's FortiOS Exists in unspecified vulnerabilities.Information may be obtained
VAR-202209-0473 CVE-2021-43080 fortinet's  FortiOS  Cross-site scripting vulnerability in CVSS V2: -
CVSS V3: 5.4
Severity: MEDIUM
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors. fortinet's FortiOS Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
VAR-202209-0452 CVE-2022-38991 plural  Huawei  Product vulnerabilities CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
VAR-202209-0449 CVE-2022-38989 plural  Huawei  Product vulnerabilities CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
VAR-202209-0256 CVE-2022-38996 Huawei  of  EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
VAR-202209-0253 CVE-2022-39000 plural  Huawei  Product vulnerabilities CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
VAR-202209-0254 CVE-2022-39004 plural  Huawei  Vulnerability related to lack of freeing memory after expiration in product CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. Huawei of EMUI , HarmonyOS , Magic UI Contains a vulnerability regarding the lack of free memory after expiration.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
VAR-202209-0172 CVE-2022-38994 Huawei  of  EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
VAR-202209-0152 CVE-2022-39007 Huawei  of  EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202209-0368 CVE-2022-39010 Huawei  of  EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
VAR-202209-0201 CVE-2022-38990 plural  Huawei  Product vulnerabilities CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
VAR-202209-0453 CVE-2021-40017 Huawei  of  EMUI  and  HarmonyOS  Input verification vulnerability in CVSS V2: -
CVSS V3: 9.8
Severity: CRITICAL
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access. Huawei of EMUI and HarmonyOS There is an input validation vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a buffer overflow vulnerability in HarmonyOS 2.0
VAR-202209-0322 CVE-2022-38979 plural  Huawei  Product vulnerabilities CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
VAR-202209-0431 CVE-2022-38995 Huawei  of  EMUI  and  HarmonyOS  Vulnerability in CVSS V2: -
CVSS V3: 7.5
Severity: HIGH
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
VAR-202209-2274 No CVE Unauthorized Access Vulnerability in Ableto Application Gateway CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Beijing Anbotong Technology Co., Ltd. is a provider of core system products and security services for visual network security. An unauthorized access vulnerability exists in the Anbotong application gateway, which can be exploited by attackers to obtain sensitive information.