VARIoT IoT vulnerabilities database

VAR-202108-0985 | CVE-2021-34565 | PEPPERL+FUCHS WirelessHART-Gateway Vulnerability in using hard-coded credentials in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials. PEPPERL+FUCHS WirelessHART-Gateway Contains a vulnerability in the use of hard-coded credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202108-0982 | CVE-2021-34562 | PEPPERL+FUCHS WirelessHART-Gateway Cross-site scripting vulnerability in |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response. PEPPERL+FUCHS WirelessHART-Gateway Exists in a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
VAR-202108-2171 | CVE-2021-34560 | PEPPERL+FUCHS WirelessHART-Gateway Vulnerability regarding insufficient protection of authentication information in |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once. PEPPERL+FUCHS WirelessHART-Gateway There are vulnerabilities in inadequate protection of credentials.Information may be obtained
VAR-202108-2271 | CVE-2021-34865 | plural NETGEAR Improper Comparison Vulnerability in Routers |
CVSS V2: 8.3 CVSS V3: 8.8 Severity: HIGH |
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-13313. plural NETGEAR An improper comparison vulnerability exists in routers. Zero Day Initiative To this vulnerability ZDI-CAN-13313 Was numbering.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202108-2549 | No CVE | Lexmark MS521dn has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
MS521dn is a printer of Lexmark International Inc.
Lexmark MS521dn has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2551 | No CVE | Ricoh (China) Investment Co., Ltd. RICOH Aficio MP171 has an unauthorized access vulnerability |
CVSS V2: 6.4 CVSS V3: - Severity: MEDIUM |
RICOH Aficio MP 171 is a printer of Ricoh (China) Investment Co., Ltd.
Ricoh (China) Investment Co., Ltd. RICOH Aficio MP171 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2552 | No CVE | Lexmark XM3250 has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Lexmark XM3250 is a printer from Lexmark International Inc.
Lexmark XM3250 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2562 | No CVE | Schneider Modicon PAC controller has industrial control equipment vulnerabilities |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
Schneider Electric M340 is a mid-range PAC industrial process and infrastructure control.
Schneider Electric M340 has vulnerabilities in industrial control equipment. Attackers can use the vulnerabilities to remotely obtain the backdoor password, use the password to connect to the password-protected controller, and perform various sensitive operations, such as stopping and running.
VAR-202108-0470 | CVE-2021-21741 | ZTE Vulnerability in deserialization of untrusted data in meeting management systems |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
There is a command execution vulnerability in a ZTE conference management system. As some services are enabled by default, the attacker could exploit this vulnerability to execute arbitrary commands by sending specific serialization command. ZTE There is a vulnerability in the conference management system regarding deserialization of untrusted data.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. ZTE ZXV10 M910 is a high-definition video server for video conferencing from China's ZTE Corporation.
ZTE ZXV10 M910 has a security vulnerability
VAR-202108-2565 | No CVE | Huawei Technologies Co., Ltd. AR2240 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Huawei AR2240 is an enterprise-level router product developed by Huawei.
Huawei Technologies Co., Ltd. AR2240 series has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2566 | No CVE | Schneider Electric Modicon PAC M580 and M340 have authorization bypass vulnerabilities |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Schneider Electric SA is a global electrical company headquartered in France.
Schneider Electric Modicon PAC M580 and M340 have an authorization bypass vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202108-2574 | No CVE | Lexmark XC2235 has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Lexmark XC2235 is a printer of Lexmark International Inc.
Lexmark XC2235 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2575 | No CVE | Lexmark X463de has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
X463de is a printer of Lexmark International Inc.
Lexmark X463de has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2580 | No CVE | FLIR-AX8 has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Teledyne FLIR focuses on the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness.
The FLIR-AX8 of the American company Phillips has a weak password vulnerability. The attacker uses the default weak password to log in to the background to obtain sensitive information.
VAR-202108-0011 | CVE-2020-15744 | Victure PC420 Out-of-bounds write vulnerabilities in smart cameras |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions. Victure PC420 Smart cameras are vulnerable to out-of-bounds writes.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202108-2555 | No CVE | Brother Industries MFC-L2710DW series has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
MFC-L2710DW series is a multi-function printer.
Brother Industries MFC-L2710DW series has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2563 | No CVE | Storage XSS vulnerability exists in the smart gateway configuration platform of Beijing Link Technology Co., Ltd. |
CVSS V2: 3.6 CVSS V3: - Severity: LOW |
Beijing Link Technology Co., Ltd. is a company that has professional Wi-Fi technology and is committed to combining Internet technology with traditional industries to help industry customers embrace the Internet and create new value for traditional industries.
The smart gateway configuration platform of Beijing Link Technology Co., Ltd. has a stored XSS vulnerability. Attackers can use this vulnerability to obtain sensitive information such as user cookies.
VAR-202108-2569 | No CVE | AXIS 207W Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
207W Network Camera is a network camera.
AXIS 207W Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2545 | No CVE | Ruijie NBR router has SQL injection vulnerability |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage.
Ruijie NBR router has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.
VAR-202108-2550 | No CVE | Unauthorized access vulnerability exists in Axis Communications AB AXIS 241SA |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
AXIS 241SA is a network video server of Axis Communications AB.
Axis Communications AB AXIS 241SA has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information and perform unauthorized operations.