VARIoT IoT vulnerabilities database
| VAR-202108-0400 | CVE-2021-21563 | Dell PowerScale OneFS Vulnerability in checking for exceptional conditions in |
CVSS V2: 4.0 CVSS V3: 6.5 Severity: MEDIUM |
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event. Dell PowerScale OneFS Exists in an exceptional condition check vulnerability.Denial of service (DoS) It may be put into a state. DELL EMC PowerScale is a scale-out storage system for unstructured data from Dell (DELL)
| VAR-202108-0399 | CVE-2021-21562 | Dell PowerScale OneFS Untrusted search path vulnerabilities in |
CVSS V2: 2.1 CVSS V3: 4.4 Severity: MEDIUM |
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control. Dell Technologies Dell PowerScale OneFS is an operating system of Dell Technologies in the United States. Offers the PowerScale OneFS operating system for scale-out NAS. Dell EMC PowerScale OneFS has a code issue vulnerability that allows a user (ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE) and (ISI PRIV SYS UPGRADE or ISI PRIV AUDIT) to provide an untrusted path that could lead to applications not running directly resources under control
| VAR-202108-0398 | CVE-2021-21553 | Dell PowerScale OneFS Vulnerability in |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest. Dell PowerScale OneFS Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Dell Technologies Dell PowerScale OneFS is an operating system of Dell Technologies in the United States. Offers the PowerScale OneFS operating system for scale-out NAS
| VAR-202108-0598 | CVE-2021-29979 | Hubs Cloud Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s primary hosting domain.*. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210618012634. Hubs Cloud Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
| VAR-202108-2331 | No CVE | Shenzhen Jixiang Tengda Technology Co., Ltd. wireless signal extender has an unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment.
The wireless signal extender of Shenzhen Jixiang Tengda Technology Co., Ltd. has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202108-2333 | No CVE | Anbottom Deep Security Gateway has file download vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Beijing Anbotong Technology Co., Ltd. is a dedicated core system product and security service provider for visual network security.
Ambton Deep Security Gateway has a file download vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2483 | No CVE | AXIS P1224-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P1224-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2484 | No CVE | AXIS P5512-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P5512-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2485 | No CVE | AXIS P5522-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P5522-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2486 | No CVE | AXIS Q6044-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS Q6044-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2487 | No CVE | AXIS P1214-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS P1214-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2488 | No CVE | Dell B2375dfw Mono MFP has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
B2375dfw Mono MFP is a printer from Dell.
Dell B2375dfw Mono MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2489 | No CVE | Unauthorized access vulnerability exists in Dell Printer E310dw |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Printer E310dwr is a printer from Dell.
Dell Printer E310dw has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2490 | No CVE | Dell B2375dnf Mono MFP has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
B2375dnf Mono MFP is a printer from Dell.
Dell B2375dnf Mono MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2492 | No CVE | Unauthorized access vulnerability exists in Cisco IP Phone CP-8851 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IP Phone CP-8851 is an enterprise-class IP phone.
Cisco IP Phone CP-8851 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2493 | No CVE | Unauthorized access vulnerability exists in Cisco IP Phone CP-8841 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IP Phone CP-8841 is an enterprise-class IP phone.
Cisco IP Phone CP-8841 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2494 | No CVE | Unauthorized access vulnerability exists in Cisco IP Phone CP-8861 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Cisco IP Phone CP-8861 is an enterprise-class IP phone.
Cisco IP Phone CP-8861 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2495 | No CVE | AXIS Q6115-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS Q6115-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2496 | No CVE | AXIS Q6045-E Network Camera has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS Q6045-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202108-2497 | No CVE | AXIS Q7424-R Video Encoder has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Axis is an IT company that specializes in providing network video solutions.
AXIS Q7424-R Video Encoder has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.