VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202108-1803 CVE-2021-36763 CODESYS V3 web server  Vulnerability in externally accessible files or directories in CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties
VAR-202108-0941 CVE-2021-31630 Open PLC Webserver v3  In  OS  Command injection vulnerability CVSS V2: 9.0
CVSS V3: 8.8
Severity: HIGH
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application. Open PLC Webserver v3 Has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202108-2324 No CVE Datang Telecom’s AC centralized management platform has a weak password vulnerability (CNVD-2021-46909) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Datang Telecom Technology Co., Ltd. is a high-tech enterprise controlled by the Institute of Telecommunications Science and Technology (Datang Telecom Technology Industry Group). Datang Telecom has formed four major industrial sectors: integrated circuit design, software and application, terminal design, and mobile Internet . Datang Telecom’s AC centralized management platform has a weak password vulnerability. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202108-2326 No CVE Hangzhou Hikvision System Technology Co., Ltd. DS-SAG200 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision System Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core. Hangzhou Hikvision System Technology Co., Ltd. DS-SAG200 has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2328 No CVE NETGEAR R8000 has a binary vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
NETGEAR R8000 is a gigabit router. NETGEAR R8000 has a binary vulnerability. Attackers can use the vulnerability to cause stack overflow.
VAR-202108-0503 CVE-2021-21576 DELL Dell EMC iDRAC9 Cross-site scripting vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link
VAR-202108-0735 CVE-2021-27953 ecobee3 lite  In  NULL  Pointer dereference vulnerability CVSS V2: 7.8
CVSS V3: 7.5
Severity: HIGH
A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Control setup process. A threat actor can exploit this vulnerability to cause a denial of service, forcing the device to reboot via a crafted HTTP request. Ecobee Ecobee3 Lite is a Wi-Fi smart thermostat from Ecobee, Canada
VAR-202108-0801 CVE-2021-33485 CODESYS Control Runtime system  Out-of-bounds write vulnerability in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. CODESYS Control Runtime system Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202108-0506 CVE-2021-21579 Dell EMC iDRAC9 Input validation error vulnerability CVSS V2: 5.8
CVSS V3: 6.1
Severity: MEDIUM
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links
VAR-202108-0505 CVE-2021-21578 Dell EMC iDRAC9 Input validation error vulnerability CVSS V2: 5.8
CVSS V3: 6.1
Severity: MEDIUM
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links
VAR-202108-2538 No CVE Denver smart wifi camera shc-150telnet command execution vulnerability CVSS V2: 6.5
CVSS V3: -
Severity: MEDIUM
Denve is a European supplier of consumer electronics products. Denver smart wifi camera shc-150telnet command execution vulnerability, attackers can use this vulnerability to execute arbitrary code.
VAR-202108-2420 No CVE Konica Minolta printers have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Both bizhub C364 and bizhub C280 are color printers launched by Konica Minolta. Many Konica Minolta printers have weak password vulnerabilities. The attacker uses a weak password to log in to the background to obtain sensitive information.
VAR-202108-2423 No CVE Panasonic Electric (China) Co., Ltd. Network Camera WV-SF138 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. Network Camera WV-SF138 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2424 No CVE Panasonic Electric (China) Co., Ltd. Network Camera WV-SF332 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. is a manufacturer mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. Network Camera WV-SF332 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-0504 CVE-2021-21577 DELL Dell EMC iDRAC9 Cross-site scripting vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain a DOM-based cross-site scripting vulnerability. A remote attacker could potentially exploit this vulnerability to run malicious HTML or JavaScript in a victim’s browser by tricking a victim in to following a specially crafted link
VAR-202108-0734 CVE-2021-27952 ecobee3 lite  Vulnerability in Using Hard Coded Credentials CVSS V2: 5.0
CVSS V3: 9.8
Severity: CRITICAL
Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain access to the password-protected bootloader environment through the serial console. ecobee3 lite Is vulnerable to the use of hard-coded credentials.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Ecobee Ecobee3 Lite is a Wi-Fi smart thermostat from Ecobee, Canada. Ecobee Ecobee3 Lite has security vulnerabilities
VAR-202108-0291 CVE-2021-22425 Huawei HarmonyOS Resource Management Error Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Root Elevating Privileges
VAR-202108-0290 CVE-2021-22424 HarmonyOS  Vulnerabilities in lack of free memory after expiration CVSS V2: 4.9
CVSS V3: 5.5
Severity: MEDIUM
A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability to cause Kernel Denial of Service. HarmonyOS Is vulnerable to a lack of free memory after expiration.Denial of service (DoS) It may be put into a state
VAR-202108-0289 CVE-2021-22423 Huawei HarmonyOS Buffer error vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to cause integer overflow
VAR-202108-0288 CVE-2021-22422 HarmonyOS  Integer overflow vulnerability in CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting. HarmonyOS Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state