VARIoT IoT vulnerabilities database

VAR-202108-1803 | CVE-2021-36763 | CODESYS V3 web server Vulnerability in externally accessible files or directories in |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties
VAR-202108-0941 | CVE-2021-31630 | Open PLC Webserver v3 In OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application. Open PLC Webserver v3 Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202108-2324 | No CVE | Datang Telecom’s AC centralized management platform has a weak password vulnerability (CNVD-2021-46909) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Datang Telecom Technology Co., Ltd. is a high-tech enterprise controlled by the Institute of Telecommunications Science and Technology (Datang Telecom Technology Industry Group). Datang Telecom has formed four major industrial sectors: integrated circuit design, software and application, terminal design, and mobile Internet .
Datang Telecom’s AC centralized management platform has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202108-2326 | No CVE | Hangzhou Hikvision System Technology Co., Ltd. DS-SAG200 has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision System Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core.
Hangzhou Hikvision System Technology Co., Ltd. DS-SAG200 has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2328 | No CVE | NETGEAR R8000 has a binary vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
NETGEAR R8000 is a gigabit router.
NETGEAR R8000 has a binary vulnerability. Attackers can use the vulnerability to cause stack overflow.
VAR-202108-0503 | CVE-2021-21576 | DELL Dell EMC iDRAC9 Cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link
VAR-202108-0735 | CVE-2021-27953 | ecobee3 lite In NULL Pointer dereference vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request. Ecobee Ecobee3 Lite is a Wi-Fi smart thermostat from Ecobee, Canada
VAR-202108-0801 | CVE-2021-33485 | CODESYS Control Runtime system Out-of-bounds write vulnerability in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. CODESYS Control Runtime system Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202108-0506 | CVE-2021-21579 | Dell EMC iDRAC9 Input validation error vulnerability |
CVSS V2: 5.8 CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links
VAR-202108-0505 | CVE-2021-21578 | Dell EMC iDRAC9 Input validation error vulnerability |
CVSS V2: 5.8 CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links
VAR-202108-2538 | No CVE | Denver smart wifi camera shc-150telnet command execution vulnerability |
CVSS V2: 6.5 CVSS V3: - Severity: MEDIUM |
Denve is a European supplier of consumer electronics products.
Denver smart wifi camera shc-150telnet command execution vulnerability, attackers can use this vulnerability to execute arbitrary code.
VAR-202108-2420 | No CVE | Konica Minolta printers have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Both bizhub C364 and bizhub C280 are color printers launched by Konica Minolta.
Many Konica Minolta printers have weak password vulnerabilities. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202108-2423 | No CVE | Panasonic Electric (China) Co., Ltd. Network Camera WV-SF138 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. Network Camera WV-SF138 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2424 | No CVE | Panasonic Electric (China) Co., Ltd. Network Camera WV-SF332 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. Network Camera WV-SF332 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-0504 | CVE-2021-21577 | DELL Dell EMC iDRAC9 Cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link
VAR-202108-0734 | CVE-2021-27952 | ecobee3 lite Vulnerability in Using Hard Coded Credentials |
CVSS V2: 5.0 CVSS V3: 9.8 Severity: CRITICAL |
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console. ecobee3 lite Is vulnerable to the use of hard-coded credentials.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Ecobee Ecobee3 Lite is a Wi-Fi smart thermostat from Ecobee, Canada.
Ecobee Ecobee3 Lite has security vulnerabilities
VAR-202108-0291 | CVE-2021-22425 | Huawei HarmonyOS Resource Management Error Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges
VAR-202108-0290 | CVE-2021-22424 | HarmonyOS Vulnerabilities in lack of free memory after expiration |
CVSS V2: 4.9 CVSS V3: 5.5 Severity: MEDIUM |
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service. HarmonyOS Is vulnerable to a lack of free memory after expiration.Denial of service (DoS) It may be put into a state
VAR-202108-0289 | CVE-2021-22423 | Huawei HarmonyOS Buffer error vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow
VAR-202108-0288 | CVE-2021-22422 | HarmonyOS Integer overflow vulnerability in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. HarmonyOS Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state