VARIoT IoT vulnerabilities database
| VAR-202209-0297 | CVE-2022-27491 | fortinet's FortiOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.001 through 6.121, 5.001 through 5.258 and before 4.086 allows a remote and unauthenticated attacker to trigger the sending of "blocked page" HTML data to an arbitrary victim via crafted TCP requests, potentially flooding the victim. fortinet's FortiOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
| VAR-202209-0268 | CVE-2022-26114 | fortinet's FortiMail Cross-site scripting vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail messages. fortinet's FortiMail Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202209-0337 | CVE-2022-40109 | TOTOLINK of A3002R Improper default permissions vulnerability in firmware |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. TOTOLINK of A3002R A firmware vulnerability related to improper default permissions exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202209-0263 | CVE-2022-26858 | Authentication vulnerabilities in multiple Dell products |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability by sending malicious input to an SMI in order to bypass security controls. Alienware m15 R6 firmware, ChengMing 3980 firmware, ChengMing 3988 Authentication vulnerabilities exist in multiple Dell products, including firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202209-0154 | CVE-2022-37840 | TOTOLINK of a860r Classic buffer overflow vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability. TOTOLINK of a860r Firmware has a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The TOTOLINK A860R is a dual-band wireless router with a maximum transmission rate of 1200Mbps. It utilizes 6-antenna dual-band concurrent technology and supports remote management via a mobile app. It is suitable for small and medium-sized businesses and home network environments. No detailed vulnerability details are currently available
| VAR-202209-0252 | CVE-2022-29053 | fortinet's FortiOS Vulnerability in |
CVSS V2: - CVSS V3: 3.3 Severity: LOW |
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it. fortinet's FortiOS Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202209-0473 | CVE-2021-43080 | fortinet's FortiOS Cross-site scripting vulnerability in |
CVSS V2: - CVSS V3: 5.4 Severity: MEDIUM |
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version 7.0.0 through 7.0.5 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack through the URI parameter via the Threat Feed IP address section of the Security Fabric External connectors. fortinet's FortiOS Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202209-0452 | CVE-2022-38991 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
| VAR-202209-0449 | CVE-2022-38989 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
| VAR-202209-0256 | CVE-2022-38996 | Huawei of EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
| VAR-202209-0253 | CVE-2022-39000 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
| VAR-202209-0254 | CVE-2022-39004 | plural Huawei Vulnerability related to lack of freeing memory after expiration in product |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The MPTCP module has the memory leak vulnerability. Successful exploitation of this vulnerability can cause memory leaks. Huawei of EMUI , HarmonyOS , Magic UI Contains a vulnerability regarding the lack of free memory after expiration.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
| VAR-202209-0172 | CVE-2022-38994 | Huawei of EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
| VAR-202209-0152 | CVE-2022-39007 | Huawei of EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202209-0368 | CVE-2022-39010 | Huawei of EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The HwChrService module has a vulnerability in permission control. Successful exploitation of this vulnerability may cause disclosure of user network information. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202209-0201 | CVE-2022-38990 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a security vulnerability in Huawei HarmonyOS, which is caused by a configuration flaw
| VAR-202209-0453 | CVE-2021-40017 | Huawei of EMUI and HarmonyOS Input verification vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access. Huawei of EMUI and HarmonyOS There is an input validation vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system. There is a buffer overflow vulnerability in HarmonyOS 2.0
| VAR-202209-0322 | CVE-2022-38979 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect data confidentiality. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be obtained. Huawei HarmonyOS is an operating system of the Chinese company Huawei. Provide a microkernel-based full-scenario distributed operating system
| VAR-202209-0431 | CVE-2022-38995 | Huawei of EMUI and HarmonyOS Vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The secure OS module has configuration defects. Successful exploitation of this vulnerability may affect system availability. Huawei of EMUI and HarmonyOS Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
| VAR-202209-2274 | No CVE | Unauthorized Access Vulnerability in Ableto Application Gateway |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Beijing Anbotong Technology Co., Ltd. is a provider of core system products and security services for visual network security.
An unauthorized access vulnerability exists in the Anbotong application gateway, which can be exploited by attackers to obtain sensitive information.