VARIoT IoT vulnerabilities database
| VAR-202208-0856 | CVE-2021-33847 | Buffer Error Vulnerability in Multiple Intel Products |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access. wi-fi 6 ax411 firmware, wi-fi 6 ax211 firmware, wi-fi 6 ax210 Multiple Intel products such as firmware contain a buffer error vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202208-0818 | CVE-2022-38130 | Keysight Technologies of sensor management server In SQL Injection vulnerability |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database file (i.e., \\<attacker-host>\sms\<attacker-db.zip>), effectively controlling the content of the database to be restored. Keysight Technologies of sensor management server for, SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202208-0642 | CVE-2022-26074 | Intel's Intel Server Platform Services Incomplete cleanup vulnerability in firmware |
CVSS V2: - CVSS V3: 4.4 Severity: MEDIUM |
Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access. Intel's Intel Server Platform Services An incomplete cleanup vulnerability exists in the firmware.Service operation interruption (DoS) It may be in a state
| VAR-202208-0855 | CVE-2021-26257 | Buffer Error Vulnerability in Multiple Intel Products |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. wi-fi 6 ax411 firmware, wi-fi 6 ax211 firmware, wi-fi 6 ax210 Multiple Intel products such as firmware contain a buffer error vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202208-0676 | CVE-2021-46304 | Vulnerabilities in multiple Siemens products |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions), CP-8021 MASTER MODULE (All versions), CP-8022 MASTER MODULE WITH GPRS (All versions). The component allows to activate a web server module which provides unauthenticated access to its web pages. This could allow an attacker to retrieve debug-level information from the component such as internal network topology or connected systems. The SICAM A8000 RTU (Remote Terminal Unit) series is a modular device family for remote control and automation applications in all areas of energy supply
| VAR-202208-0853 | CVE-2021-26950 | Out-of-bounds read vulnerability in multiple Intel products |
CVSS V2: - CVSS V3: 5.5 Severity: MEDIUM |
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access. wi-fi 6 ax411 firmware, wi-fi 6 ax211 firmware, wi-fi 6 ax210 Multiple Intel products, including firmware, contain out-of-bounds read vulnerabilities.Service operation interruption (DoS) It may be in a state
| VAR-202208-0854 | CVE-2021-23179 | Out-of-bounds read vulnerability in multiple Intel products |
CVSS V2: - CVSS V3: 7.1 Severity: HIGH |
Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access. wi-fi 6 ax411 firmware, wi-fi 6 ax211 firmware, wi-fi 6 ax210 Multiple Intel products, including firmware, contain out-of-bounds read vulnerabilities.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202208-0817 | CVE-2022-37006 | Huawei of EMUI and HarmonyOS Vulnerability regarding improper default permissions in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability. Huawei of EMUI and HarmonyOS There is a vulnerability in improper default permissions.Service operation interruption (DoS) It may be in a state. HUAWEI EMUI is a mobile operating system developed by China Huawei (HUAWEI) based on Android
| VAR-202208-0814 | CVE-2021-33646 | feep.net of libtar Vulnerability related to lack of free memory after expiration in products from other vendors |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak. feep.net of libtar Products from multiple other vendors are vulnerable to lack of freeing memory after expiration.Service operation interruption (DoS) It may be in a state. openEuler is an operating system of the Open Atom Open Source Foundation. There are security vulnerabilities in openEuler 20.03-LTS-SP1, 20.03-LTS-SP3 and 22.03-LTS versions. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: libtar security update
Advisory ID: RHSA-2023:2898-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:2898
Issue date: 2023-05-16
CVE Names: CVE-2021-33643 CVE-2021-33644 CVE-2021-33645
CVE-2021-33646
====================================================================
1. Summary:
An update for libtar is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64
3. Description:
The libtar packages contain a C library for manipulating tar archives. The
library supports both the strict POSIX tar format and many of the commonly
used GNU extensions.
Security Fix(es):
* libtar: out-of-bounds read in gnu_longlink (CVE-2021-33643)
* libtar: out-of-bounds read in gnu_longname (CVE-2021-33644)
* libtar: memory leak found in th_read() function (CVE-2021-33645)
* libtar: memory leak found in th_read() function (CVE-2021-33646)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.8 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Package List:
Red Hat Enterprise Linux AppStream (v. 8):
Source:
libtar-1.2.20-17.el8.src.rpm
aarch64:
libtar-1.2.20-17.el8.aarch64.rpm
libtar-debuginfo-1.2.20-17.el8.aarch64.rpm
libtar-debugsource-1.2.20-17.el8.aarch64.rpm
ppc64le:
libtar-1.2.20-17.el8.ppc64le.rpm
libtar-debuginfo-1.2.20-17.el8.ppc64le.rpm
libtar-debugsource-1.2.20-17.el8.ppc64le.rpm
s390x:
libtar-1.2.20-17.el8.s390x.rpm
libtar-debuginfo-1.2.20-17.el8.s390x.rpm
libtar-debugsource-1.2.20-17.el8.s390x.rpm
x86_64:
libtar-1.2.20-17.el8.i686.rpm
libtar-1.2.20-17.el8.x86_64.rpm
libtar-debuginfo-1.2.20-17.el8.i686.rpm
libtar-debuginfo-1.2.20-17.el8.x86_64.rpm
libtar-debugsource-1.2.20-17.el8.i686.rpm
libtar-debugsource-1.2.20-17.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-33643
https://access.redhat.com/security/cve/CVE-2021-33644
https://access.redhat.com/security/cve/CVE-2021-33645
https://access.redhat.com/security/cve/CVE-2021-33646
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBZGNwdNzjgjWX9erEAQjfPw//SoG/pVemP1peDGxUFDfBMBbldrFWpNro
Te4tTe3YAkVgQgtnGZ8n3Arlrryk+3wfgQj3u9gdUj1w14YyEZC8hpWLCXI5iw/P
Ul4dHHOnO0UW568dkaqUeJjl02o2ugRp2RZVt14yuZqLKmF9WCJW7lCZQLoqCIVp
7P3vZOQBlyU6BuGXO4Th86fpLDEZCboBQDA2QeNFvt+qNwvNxgb3A05217tfXnZ4
EpltZPIrl8pzEmmWA09XeFgIm5GXNiWjjR/fF3OHSgQ9cmXnafxWSBNiDlzHNQCk
0/z5gcvl+BJLceQoZBo6hdldHCiOF20jCxr8Nb/3sSJ+zAqQqqNsnDQ1TGs2GMDz
Mx5JECSk0p79MMKR0mrP2NbCqxqEsqOkjinIa0PDlKNPFbEikA4l7fXu58KyHsr/
V9otYHvD1ilS7cTw1FGi198oodCofA+euZCQBNnWuFbnrCo1cyRBN6mjCMZwDgww
ZhNWOUvAmkhtC5ebBb8zuMJ73ojSwiv886kJbEjDlG7SDGbMPHxEAgTHWZp5l+jw
z36m+SegsAXE/UKHRYTFriRA5p1pyq/AVUMwhMXvQhwwNxPl2wsaUOJGFBw3Fu3n
bAFXpxAngQvELHEFOtmL9fzbnFo93OTkvuz9tJpbvNOCmDBJJEN6Znhic0iWzT0p
kHiakPvkvj4=I+bk
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202208-0611 | CVE-2022-36323 | Vulnerabilities in multiple Siemens products |
CVSS V2: 10.0 CVSS V3: 9.1 Severity: CRITICAL |
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. SCALANCE M-800 firmware, SCALANCE S615 firmware, SCALANCE SC-600 Multiple Siemens products such as firmware have unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. SCALANCE M-800, MUM-800 and S615 and RUGGEDCOM RM1224 industrial routers are used for secure remote access to plants via mobile networks (e.g. GPRS or UMTS) and have integrated security functions of firewalls to prevent unauthorized access, as well as VPNs to Secure data transmission. SCALANCE SC-600 devices (SC622-2C, SC632-2C, SC636-2C, SC642-2C, SC646-2C) are used to protect trusted industrial networks from untrusted network attacks. They allow filtering incoming and outgoing network connections in different ways. The SCALANCE W-1700 product is a wireless communication device based on the IEEE 802.11ac standard. SCALANCE W-700 products are wireless communication devices based on the IEEE 802.11ax standard. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLC) or human machine interfaces (HMI).
A command injection vulnerability exists in Siemens SCALANCE products, which results from an affected device failing to properly filter input fields. A vulnerability has been identified in SCALANCE M-800 / S615 (All versions), SCALANCE SC-600 family (All versions < V2.3.1), SCALANCE W-1700 IEEE 802.11ac family (All versions), SCALANCE W-700 IEEE 802.11ax family (All versions), SCALANCE W-700 IEEE 802.11n family (All versions), SCALANCE XB-200 switch family (All versions), SCALANCE XC-200 switch family (All versions), SCALANCE XF-200BA switch family (All versions), SCALANCE XM-400 Family (All versions), SCALANCE XP-200 switch family (All versions), SCALANCE XR-300WG switch family (All versions), SCALANCE XR-500 Family (All versions)
| VAR-202208-0945 | CVE-2021-33644 | feep.net of libtar Out-of-Bounds Read Vulnerability in Other Vendors' Products |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read. feep.net of libtar Products from other vendors have out-of-bounds read vulnerabilities.Information is obtained and service operation is interrupted (DoS) It may be in a state. openEuler is an operating system of the Open Atom Open Source Foundation. There are security vulnerabilities in openEuler 20.03-LTS-SP1, 20.03-LTS-SP3 and 22.03-LTS versions of the Open Atom Open Source Foundation. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: libtar security update
Advisory ID: RHSA-2023:2898-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2023:2898
Issue date: 2023-05-16
CVE Names: CVE-2021-33643 CVE-2021-33644 CVE-2021-33645
CVE-2021-33646
====================================================================
1. Summary:
An update for libtar is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64
3. Description:
The libtar packages contain a C library for manipulating tar archives. The
library supports both the strict POSIX tar format and many of the commonly
used GNU extensions.
Security Fix(es):
* libtar: out-of-bounds read in gnu_longlink (CVE-2021-33643)
* libtar: out-of-bounds read in gnu_longname (CVE-2021-33644)
* libtar: memory leak found in th_read() function (CVE-2021-33645)
* libtar: memory leak found in th_read() function (CVE-2021-33646)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.8 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
2121289 - CVE-2021-33643 libtar: out-of-bounds read in gnu_longlink
2121292 - CVE-2021-33644 libtar: out-of-bounds read in gnu_longname
2121295 - CVE-2021-33645 libtar: memory leak found in th_read() function
2121297 - CVE-2021-33646 libtar: memory leak found in th_read() function
6. Package List:
Red Hat Enterprise Linux AppStream (v. 8):
Source:
libtar-1.2.20-17.el8.src.rpm
aarch64:
libtar-1.2.20-17.el8.aarch64.rpm
libtar-debuginfo-1.2.20-17.el8.aarch64.rpm
libtar-debugsource-1.2.20-17.el8.aarch64.rpm
ppc64le:
libtar-1.2.20-17.el8.ppc64le.rpm
libtar-debuginfo-1.2.20-17.el8.ppc64le.rpm
libtar-debugsource-1.2.20-17.el8.ppc64le.rpm
s390x:
libtar-1.2.20-17.el8.s390x.rpm
libtar-debuginfo-1.2.20-17.el8.s390x.rpm
libtar-debugsource-1.2.20-17.el8.s390x.rpm
x86_64:
libtar-1.2.20-17.el8.i686.rpm
libtar-1.2.20-17.el8.x86_64.rpm
libtar-debuginfo-1.2.20-17.el8.i686.rpm
libtar-debuginfo-1.2.20-17.el8.x86_64.rpm
libtar-debugsource-1.2.20-17.el8.i686.rpm
libtar-debugsource-1.2.20-17.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-33643
https://access.redhat.com/security/cve/CVE-2021-33644
https://access.redhat.com/security/cve/CVE-2021-33645
https://access.redhat.com/security/cve/CVE-2021-33646
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.8_release_notes/index
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBZGNwdNzjgjWX9erEAQjfPw//SoG/pVemP1peDGxUFDfBMBbldrFWpNro
Te4tTe3YAkVgQgtnGZ8n3Arlrryk+3wfgQj3u9gdUj1w14YyEZC8hpWLCXI5iw/P
Ul4dHHOnO0UW568dkaqUeJjl02o2ugRp2RZVt14yuZqLKmF9WCJW7lCZQLoqCIVp
7P3vZOQBlyU6BuGXO4Th86fpLDEZCboBQDA2QeNFvt+qNwvNxgb3A05217tfXnZ4
EpltZPIrl8pzEmmWA09XeFgIm5GXNiWjjR/fF3OHSgQ9cmXnafxWSBNiDlzHNQCk
0/z5gcvl+BJLceQoZBo6hdldHCiOF20jCxr8Nb/3sSJ+zAqQqqNsnDQ1TGs2GMDz
Mx5JECSk0p79MMKR0mrP2NbCqxqEsqOkjinIa0PDlKNPFbEikA4l7fXu58KyHsr/
V9otYHvD1ilS7cTw1FGi198oodCofA+euZCQBNnWuFbnrCo1cyRBN6mjCMZwDgww
ZhNWOUvAmkhtC5ebBb8zuMJ73ojSwiv886kJbEjDlG7SDGbMPHxEAgTHWZp5l+jw
z36m+SegsAXE/UKHRYTFriRA5p1pyq/AVUMwhMXvQhwwNxPl2wsaUOJGFBw3Fu3n
bAFXpxAngQvELHEFOtmL9fzbnFo93OTkvuz9tJpbvNOCmDBJJEN6Znhic0iWzT0p
kHiakPvkvj4=I+bk
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202208-0902 | CVE-2022-33929 | Dell's Dell Wyse Management Suite Cross-site scripting vulnerability in |
CVSS V2: - CVSS V3: 6.1 Severity: MEDIUM |
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation may lead to information disclosure, session theft, or client-side request forgery. The offering includes Wyse endpoint centralized management, asset tracking and automatic device discovery
| VAR-202208-0868 | CVE-2021-33126 | Vulnerabilities in multiple Intel products |
CVSS V2: - CVSS V3: 4.4 Severity: MEDIUM |
Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before versions 8.5 and 1.5.5 may allow a privileged user to potentially enable denial of service via local access. ethernet controller xxv710 firmware, ethernet controller xl710 firmware, ethernet controller v710 Multiple Intel products such as firmware have unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
| VAR-202208-0900 | CVE-2022-33926 | Dell's Dell Wyse Management Suite Vulnerability in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked. The offering includes Wyse endpoint centralized management, asset tracking and automatic device discovery
| VAR-202208-1071 | CVE-2022-21812 | Intel's Intel Hardware Accelerated Execution Manager Vulnerability in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's Intel Hardware Accelerated Execution Manager Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202208-0888 | CVE-2021-40040 | plural Huawei Product vulnerabilities |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulnerability may affect confidentiality. Huawei of EMUI , HarmonyOS , Magic UI Exists in unspecified vulnerabilities.Information may be obtained. HUAWEI EMUI is a mobile operating system developed based on Android
| VAR-202208-0822 | CVE-2022-26344 | Intel's single event api Vulnerability regarding improper default permissions in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's single event api There is a vulnerability in improper default permissions.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202208-1049 | CVE-2022-33928 | Dell's Dell Wyse Management Suite Vulnerability in plaintext storage of important information in |
CVSS V2: - CVSS V3: 8.8 Severity: HIGH |
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. (DoS) It may be in a state. The offering includes Wyse endpoint centralized management, asset tracking and automatic device discovery
| VAR-202208-0821 | CVE-2022-26374 | Intel's single event api Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access. Intel's single event api Exists in a vulnerability in an element of an uncontrolled search path.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202208-1002 | CVE-2022-25999 | Intel's enpirion digital power configurator gui Vulnerability regarding uncontrolled search path elements in |
CVSS V2: - CVSS V3: 7.8 Severity: HIGH |
Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access. (DoS) It may be in a state