VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202107-1852 No CVE Panasonic Corporation (China) Co., Ltd. multiple models of network cameras have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other products. Multiple network cameras of Panasonic Electric (China) Co., Ltd. have unauthorized access vulnerabilities. Attackers can use the vulnerabilities to obtain sensitive information.
VAR-202107-1853 No CVE Brickcom-MD-300Np-360P has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc. Brickcom-MD-300Np-360P has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1854 No CVE BRIC Communication Technology Co., Ltd. VD-130Ae camera has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Brickcom Corporation (Brickcom Corporation) is composed of a research and development team with rich experience in the surveillance industry, and develops digital surveillance products with advanced technology. Including millions of video network cameras, wireless network cameras, video servers, 3G video transmission (NVR) embedded network hard disk video recorders, CMS client platform systems, etc. The VD-130Ae camera of BRICS Communication Technology Co., Ltd. has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202107-1855 No CVE Panasonic Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SPN310 and WV-SPN310A have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1856 No CVE Panasonic Electric (China) Co., Ltd. WV-SPW532L has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SPW532L has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1857 No CVE Panasonic Electric (China) Co., Ltd. WV-SPN310V has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SPN310V has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1858 No CVE Panasonic Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. was established in 1994 and is mainly responsible for the sales and after-sales service of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-SP305 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1859 No CVE Unauthorized access vulnerability exists in Teledyne FLIR Brickstream 2200 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Teledyne FLIR is a company specializing in the design, development, production, marketing and promotion of professional technologies for enhancing situational awareness. Teledyne FLIR Brickstream 2200 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1860 No CVE Yawcam has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
The official version of Yawcam (win7 camera software) is a camera capture. Yawcam (win7 camera software) easily helps users perform accurate live broadcasts outdoors, and the official version of Yawcam (win7 camera software) can also quickly intercept the played images. , And save it in a local file. Yawcam has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1861 No CVE HP Color LaserJet MFP M277n has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP-Color-LaserJet-MFP-M277n is a printer of HP Trading (Shanghai) Co., Ltd. HP Color LaserJet MFP M277n has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1862 No CVE HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hewlett-Packard Trading (Shanghai) Co., Ltd. was established in 1999. Its business scope includes: computer software and hardware equipment, printing equipment, imaging equipment, communication equipment, electronic products and related parts and components of the above products. HP LaserJet 100 colorMFP M175nw and HP Color LaserJet MFP M183fw have unauthorized access vulnerabilities, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1863 No CVE HP LaserJet Pro M706n has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HP LaserJet Pro M706n is a printer of Hewlett-Packard Trading (Shanghai) Co., Ltd. The HP LaserJet Pro M706n has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1864 No CVE Panasonic Electric (China) Co., Ltd. WV-X6531 has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Matsushita Electric (China) Co., Ltd. is mainly responsible for the sales and after-sales service activities of home appliances, systems, environment, components and other commodities. Matsushita Electric (China) Co., Ltd. WV-X6531 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1865 No CVE 3Com-OfficeConnect ADSL Wireless 11g Firewall Router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Founded in 1979, 3Com is an American equipment provider that provides security products, integrated voice equipment, and data network solutions for enterprises of all sizes. 3Com-OfficeConnect ADSL Wireless 11g Firewall Router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1757 No CVE ZTE Corporation ZXV10 I508C has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXV10 I508C is a wireless router of ZTE Corporation. ZTE Corporation ZXV10 I508C has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1758 No CVE Unauthorized access vulnerability exists in HP ENVY 4500 e-All-in-One Printer series CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hewlett-Packard Trading (Shanghai) Co., Ltd. is a company whose business scope includes computer software and hardware equipment, printing equipment, imaging equipment, and communication equipment. The HP ENVY 4500 e-All-in-One Printer series has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1759 No CVE HP PageWide Pro 477dw MFP has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hewlett-Packard Trading (Shanghai) Co., Ltd. is a company whose business scope includes computer software and hardware equipment, printing equipment, imaging equipment, and communication equipment. The HP PageWide Pro 477dw MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-1760 No CVE Anbottom Deep Security Gateway has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Beijing Anbotong Technology Co., Ltd. (abbreviated as “Anbotong”), started in 2011, with the concept of "seeing security and experiencing value" as the core, is a dedicated core system product and security service provider for visual network security. Anbottom Deep Security Gateway has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202107-0200 CVE-2020-20741 Beckhoff Automation GmbH & Co. KG CX9020  Firmware vulnerabilities CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if the credentials are incorrect. KG CX9020 There are unspecified vulnerabilities in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
VAR-202107-0025 CVE-2020-14032 ASRock 4x4 BOX-R1000  Vulnerability in privilege management in CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM. ASRock 4x4 BOX-R1000 Exists in a permission management vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state