VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202111-1757 CVE-2021-21916 Advantech R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 6.5
CVSS V3: 8.8
Severity: HIGH
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. Advantech R-SeeNet for, SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202111-1752 CVE-2021-21919 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ord’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack
VAR-202111-1756 CVE-2021-21915 Advantech R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 6.5
CVSS V3: 8.8
Severity: HIGH
An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery. Advantech R-SeeNet for, SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202111-1751 CVE-2021-21918 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter. However, the high privilege super-administrator account needs to be used to achieve exploitation without cross-site request forgery attack
VAR-202111-1735 CVE-2021-21923 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘company_filter’ parameter with the administrative account or through cross-site request forgery
VAR-202111-1734 CVE-2021-21922 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘username_filter’ parameter with the administrative account or through cross-site request forgery
VAR-202111-1733 CVE-2021-21921 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery
VAR-202111-1732 CVE-2021-21937 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1731 CVE-2021-21920 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘surname_filter’ parameter with the administrative account or through cross-site request forgery
VAR-202111-1730 CVE-2021-21936 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 6.5
CVSS V3: 8.8
Severity: HIGH
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery. R-SeeNet for, SQL There is an injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202111-1729 CVE-2021-21935 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter2’ parameter. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1728 CVE-2021-21934 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1727 CVE-2021-21933 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1726 CVE-2021-21932 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1725 CVE-2021-21931 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1724 CVE-2021-21930 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1723 CVE-2021-21929 R-SeeNet  In  SQL  Injection vulnerability CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery
VAR-202111-1129 CVE-2021-36321 Dell Networking X-Series input validation error vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending specially crafted data to trigger a denial of service. Dell Networking X-Series is a series of intelligent network management switches from Dell (Dell) in the United States
VAR-202111-1130 CVE-2021-36320 Dell Networking X-Series  Insufficient Entropy Vulnerability in Firmware CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID. Dell Networking X-Series Firmware has an entropy deficiency vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Dell Networking X-Series is a series of intelligent network management switches from Dell (Dell) in the United States
VAR-202111-1159 CVE-2021-36322 Dell Networking X-Series  Injection Vulnerability in Firmware CVSS V2: 5.8
CVSS V3: 6.1
Severity: MEDIUM
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections. Dell Networking X-Series is a series of intelligent network management switches from Dell (Dell) in the United States