VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202108-0400 CVE-2021-21563 Dell PowerScale OneFS  Vulnerability in checking for exceptional conditions in CVSS V2: 4.0
CVSS V3: 6.5
Severity: MEDIUM
Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its auditing component.This can lead to an authenticated user with low-privileges to trigger a denial of service event. Dell PowerScale OneFS Exists in an exceptional condition check vulnerability.Denial of service (DoS) It may be put into a state. DELL EMC PowerScale is a scale-out storage system for unstructured data from Dell (DELL)
VAR-202108-0399 CVE-2021-21562 Dell PowerScale OneFS  Untrusted search path vulnerabilities in CVSS V2: 2.1
CVSS V3: 4.4
Severity: MEDIUM
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PRIV_LOGIN_SSH or ISI_PRIV_LOGIN_CONSOLE) and (ISI_PRIV_SYS_UPGRADE or ISI_PRIV_AUDIT) to provide an untrusted path which can lead to run resources that are not under the application’s direct control. Dell Technologies Dell PowerScale OneFS is an operating system of Dell Technologies in the United States. Offers the PowerScale OneFS operating system for scale-out NAS. Dell EMC PowerScale OneFS has a code issue vulnerability that allows a user (ISI PRIV LOGIN SSH or ISI PRIV LOGIN CONSOLE) and (ISI PRIV SYS UPGRADE or ISI PRIV AUDIT) to provide an untrusted path that could lead to applications not running directly resources under control
VAR-202108-0398 CVE-2021-21553 Dell PowerScale OneFS  Vulnerability in CVSS V2: 7.2
CVSS V3: 8.8
Severity: HIGH
Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific conditions, this can allow the CompAdmin user to elevate privileges and break out of Compliance mode. This is a critical vulnerability and Dell recommends upgrading at the earliest. Dell PowerScale OneFS Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Dell Technologies Dell PowerScale OneFS is an operating system of Dell Technologies in the United States. Offers the PowerScale OneFS operating system for scale-out NAS
VAR-202108-0598 CVE-2021-29979 Hubs Cloud  Cross-site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instance’s primary hosting domain.*. This vulnerability affects Hubs Cloud < mozillareality/reticulum/1.0.1/20210618012634. Hubs Cloud Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with
VAR-202108-2331 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. wireless signal extender has an unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. The wireless signal extender of Shenzhen Jixiang Tengda Technology Co., Ltd. has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202108-2333 No CVE Anbottom Deep Security Gateway has file download vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Beijing Anbotong Technology Co., Ltd. is a dedicated core system product and security service provider for visual network security. Ambton Deep Security Gateway has a file download vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2483 No CVE AXIS P1224-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P1224-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2484 No CVE AXIS P5512-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P5512-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2485 No CVE AXIS P5522-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P5522-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2486 No CVE AXIS Q6044-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS Q6044-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2487 No CVE AXIS P1214-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS P1214-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2488 No CVE Dell B2375dfw Mono MFP has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
B2375dfw Mono MFP is a printer from Dell. Dell B2375dfw Mono MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2489 No CVE Unauthorized access vulnerability exists in Dell Printer E310dw CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Printer E310dwr is a printer from Dell. Dell Printer E310dw has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2490 No CVE Dell B2375dnf Mono MFP has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
B2375dnf Mono MFP is a printer from Dell. Dell B2375dnf Mono MFP has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2492 No CVE Unauthorized access vulnerability exists in Cisco IP Phone CP-8851 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco IP Phone CP-8851 is an enterprise-class IP phone. Cisco IP Phone CP-8851 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2493 No CVE Unauthorized access vulnerability exists in Cisco IP Phone CP-8841 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco IP Phone CP-8841 is an enterprise-class IP phone. Cisco IP Phone CP-8841 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2494 No CVE Unauthorized access vulnerability exists in Cisco IP Phone CP-8861 CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Cisco IP Phone CP-8861 is an enterprise-class IP phone. Cisco IP Phone CP-8861 has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2495 No CVE AXIS Q6115-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS Q6115-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2496 No CVE AXIS Q6045-E Network Camera has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS Q6045-E Network Camera has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202108-2497 No CVE AXIS Q7424-R Video Encoder has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Axis is an IT company that specializes in providing network video solutions. AXIS Q7424-R Video Encoder has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.