VARIoT IoT vulnerabilities database
| VAR-202107-1852 | No CVE | Panasonic Corporation (China) Co., Ltd. multiple models of network cameras have unauthorized access vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other products.
Multiple network cameras of Panasonic Electric (China) Co., Ltd. have unauthorized access vulnerabilities. Attackers can use the vulnerabilities to obtain sensitive information.
| VAR-202107-1853 | No CVE | Brickcom-MD-300Np-360P has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc.
Brickcom-MD-300Np-360P has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1854 | No CVE | BRIC Communication Technology Co., Ltd. VD-130Ae camera has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc.
The VD-130Ae camera of BRICS Communication Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202107-1855 | No CVE | Panasonic Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1856 | No CVE | Panasonic Electric (China) Co., Ltd. WV-SPW532L has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-SPW532L has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1857 | No CVE | Panasonic Electric (China) Co., Ltd. WV-SPN310V has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-SPN310V has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1858 | No CVE | Panasonic Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1859 | No CVE | Unauthorized access vulnerability exists in Teledyne FLIR Brickstream 2200 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Teledyne FLIR is a company specializing in the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness.
Teledyne FLIR Brickstream 2200 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1860 | No CVE | Yawcam has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The official version of Yawcam (win7 camera software) is a camera capture. Yawcam (win7 camera software) easily helps users perform accurate live broadcasts outdoors, and the official version of Yawcam (win7 camera software) can also quickly intercept the played images. , And save it in a local file.
Yawcam has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1861 | No CVE | HP Color LaserJet MFP M277n has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP-Color-LaserJet-MFP-M277n is a printer of HP Trading (Shanghai) Co., Ltd.
HP Color LaserJet MFP M277n has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1862 | No CVE | HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hewlett-Packard Trading (Shanghai) Co., Ltd. was established in 1999. Its business scope includes: computer software and hardware equipment, printing equipment, imaging equipment, communication equipment, electronic products and related parts and components of the above products.
HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1863 | No CVE | HP LaserJet Pro M706n has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HP LaserJet Pro M706n is a printer of Hewlett-Packard Trading (Shanghai) Co., Ltd.
The HP LaserJet Pro M706n has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1864 | No CVE | Panasonic Electric (China) Co., Ltd. WV-X6531 has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Matsushita Electric (China) Co., Ltd. is mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities.
Matsushita Electric (China) Co., Ltd. WV-X6531 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1865 | No CVE | 3Com-OfficeConnect ADSL Wireless 11g Firewall Router has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Founded in 1979, 3Com is an American equipment provider that provides security products, integrated voice equipment, and data network solutions for enterprises of all sizes.
3Com-OfficeConnect ADSL Wireless 11g Firewall Router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1757 | No CVE | ZTE Corporation ZXV10 I508C has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ZXV10 I508C is a wireless router of ZTE Corporation.
ZTE Corporation ZXV10 I508C has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1758 | No CVE | Unauthorized access vulnerability exists in HP ENVY 4500 e-All-in-One Printer series |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hewlett-Packard Trading (Shanghai) Co., Ltd. is a company whose business scope includes computer software and hardware equipment, printing equipment, imaging equipment, and communication equipment.
The HP ENVY 4500 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1759 | No CVE | HP PageWide Pro 477dw MFP has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hewlett-Packard Trading (Shanghai) Co., Ltd. is a company whose business scope includes computer software and hardware equipment, printing equipment, imaging equipment, and communication equipment.
The HP PageWide Pro 477dw MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-1760 | No CVE | Anbottom Deep Security Gateway has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Beijing Anbotong Technology Co., Ltd. (abbreviated as “Anbotong”), started in 2011, with the concept of "seeing security and experiencing value" as the core, is a dedicated core system product and security service provider for visual network security.
Anbottom Deep Security Gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202107-0200 | CVE-2020-20741 | Beckhoff Automation GmbH & Co. KG CX9020 Firmware vulnerabilities |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect. KG CX9020 There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202107-0025 | CVE-2020-14032 | ASRock 4x4 BOX-R1000 Vulnerability in privilege management in |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. ASRock 4x4 BOX-R1000 Exists in a permission management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state