VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202106-1142 CVE-2021-30357 Linux  for  SSL Network Extender  Vulnerability related to information leakage due to error message in client CVSS V2: 5.0
CVSS V3: 5.3
Severity: MEDIUM
SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access
VAR-202106-0343 CVE-2020-24511 Intel Processors Information disclosure vulnerability CVSS V2: 2.1
CVSS V3: 6.5
Severity: MEDIUM
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. Intel Processors (Intel processors) are Intel Corporation's processors that interpret computer instructions and process data in computer software. An authenticated attacker could exploit this vulnerability to obtain sensitive information. For the stable distribution (buster), these problems have been fixed in version 3.20210608.2~deb10u1. Note that there are two reported regressions; for some CoffeeLake CPUs this update may break iwlwifi (https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/56) and some for Skylake R0/D0 CPUs on systems using a very outdated firmware/BIOS, the system may hang on boot: (https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/31) If you are affected by those issues, you can recover by disabling microcode loading on boot (as documented in README.Debian (also available online at https://salsa.debian.org/hmh/intel-microcode/-/blob/master/debian/README.Debian)) We recommend that you upgrade your intel-microcode packages. For the detailed security status of intel-microcode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/intel-microcode Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmDXan0ACgkQEMKTtsN8 Tja9aQ//f1dHsEghQsedGnkMCIa2qLi12UFtb4yW7TYV6uwloqbYZMbymvoXYOAB haasn+yCaGUkXuAHxcGvZuN41EkRhdG4LfS5qoZxPMsw84ETjpV2Ohwhuqwf9P20 9pqV1QLjVPCMiCqvHatkzyRNPtRhIh0uCRx5HtIeOEyKTwhVnUJrrljUXCzMDviD 3As0n0yVUPDIcJdaVxp5mxyebf1NyIYMR+7wmzTBOhK6i+rEE4NkKGkcsYBIM1ch AdTQNHv78QZld6ixL8iCUe1NsSugZ2QjbVL1BLW45fJv3f0BIF5uo6LBzbiJlN/6 xWwOdFTfqW1ORyr0k6JQ+yKz3oSE+jfUStwf+zegWOjYes5gGaA/nATzzNwwFfCQ qDqMmnN26qMI3MswP50ESkNs2JTK3955cIJjnscp5DeFArDuCFKh9wcqSZ46/QCE GVRi+F/Dh3JQxv/jP8jfLhCvkBptuendGo9qK5v22QoeCRoHS16dLu7HHP34hRrw k//EgtP35pD9eTNiIsxhmx3qTPD0gbQbcMG/5NTVtpNqsffAxYtqTy8+/4lfPkNn AYtYrrG6tjEHe1gasLkjthB7c0YLzPLdNyZkNIk6XZ2YIhx18N80c7gTBERSJ1Sh 9lmsnX3+5GWM7Fx2NN2vL5xIEo0einMJCyTlNMRDLim2ix1vpZg= =RVf2 -----END PGP SIGNATURE----- . 6 ELS) - i386, x86_64 3. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: microcode_ctl security, bug fix and enhancement update Advisory ID: RHSA-2021:2303-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:2303 Issue date: 2021-06-08 CVE Names: CVE-2020-24489 CVE-2020-24511 CVE-2020-24512 CVE-2020-24513 ==================================================================== 1. Summary: An update for microcode_ctl is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.6) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.6) - x86_64 3. Description: The microcode_ctl packages provide microcode updates for Intel. Security Fix(es): * hw: vt-d related privilege escalation (CVE-2020-24489) * hw: improper isolation of shared resources in some Intel Processors (CVE-2020-24511) * hw: observable timing discrepancy in some Intel Processors (CVE-2020-24512) * hw: information disclosure on some Intel Atom processors (CVE-2020-24513) Bug Fix(es) and Enhancement(s): * Update Intel CPU microcode to microcode-20210525 release 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1962650 - CVE-2020-24489 hw: vt-d related privilege escalation 1962666 - CVE-2020-24513 hw: information disclosure on some Intel Atom processors 1962702 - CVE-2020-24511 hw: improper isolation of shared resources in some Intel Processors 1962722 - CVE-2020-24512 hw: observable timing discrepancy in some Intel Processors 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.6): Source: microcode_ctl-2.1-47.21.el7_6.src.rpm x86_64: microcode_ctl-2.1-47.21.el7_6.x86_64.rpm microcode_ctl-debuginfo-2.1-47.21.el7_6.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.6): Source: microcode_ctl-2.1-47.21.el7_6.src.rpm x86_64: microcode_ctl-2.1-47.21.el7_6.x86_64.rpm microcode_ctl-debuginfo-2.1-47.21.el7_6.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.6): Source: microcode_ctl-2.1-47.21.el7_6.src.rpm x86_64: microcode_ctl-2.1-47.21.el7_6.x86_64.rpm microcode_ctl-debuginfo-2.1-47.21.el7_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-24489 https://access.redhat.com/security/cve/CVE-2020-24511 https://access.redhat.com/security/cve/CVE-2020-24512 https://access.redhat.com/security/cve/CVE-2020-24513 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYMAkptzjgjWX9erEAQjQaxAAiXuFV2AZ5UNVNR29EFFEaHsHDTLaeYNm ibgw81yBpSZopPqtVYoznk9JAYc2YSrgbq0/BxC+rWHRTGPom5lZumlkqc+Nkjon sGx6SXU5q9M/nPutM/p5afTXNaHbZVQojjeP9VIpF1qz94JRcJisrumAW/sS27/v Ie6wqizvXNJZq30FOmgAq3vSXJpvakZYrBZoRvdm3MUx3rqiy/Sn62VtexeJoWJf 7BVF9y24rn2r9BuG6QNKGnYTxuUHAfcTAy5laJZ7EWdpEXcSZG6SV6x40Zdg6TaV 8x6PFSbvb2woGvWfFr5so9I92X1z9MCh4vQ5hmPnoHHREXpDKcDjvmfnStNkKD3F kOvf99Ph7E4Th/NhFwAczspiZEJYbvZ7ZenKQwWd2lGnEzFdPU5g5c3n+WVyN1qZ psD/uZlryQyIUyvRPowGppm/vJfyIiDKr+yUpq3AGscs9ASpnH6120ClaQx3KutT gpUbnKDxAW7UMlg5V4A9y5jJBgW8cZGH4qKc9KeDOj1MOjOhrfClInKhfqqY6YF1 8ulHpTKFyXzFjKBST1PKhCQQ2HhG74GoG147R0yHZw+9T0+o3ovlEQTxD2yVgGua 7LQ/vJotdgvBEaYoWTz6WwphiYQpFbbyQ6E0qplPVJMMmFKhDpNKS+ama5CHnfUF 6I3FlLzt1EU=YG8p -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce
VAR-202106-2044 No CVE Ren Zixing audit gateway has command execution vulnerabilities CVSS V2: 9.0
CVSS V3: -
Severity: HIGH
Ren Zixing Network Technology Co., Ltd. is the most comprehensive provider of large-scale cyberspace security protection solutions in China. Ren Zixing's audit gateway has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202106-2046 No CVE TP-LINK Archer C9 has weak password vulnerability CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Archer C9 is a wireless router product. TP-LINK Archer C9 has a weak password vulnerability. Attackers can use vulnerabilities to log in to the background of the system to obtain sensitive information.
VAR-202106-2047 No CVE Four-Faith of Xiamen Four-Faith Communication Technology Co., Ltd. has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Four-Faith is a router product of Xiamen Four-Faith Communication Technology Co., Ltd. Four-Faith, Xiamen Four-Faith Communication Technology Co., Ltd. has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202106-2241 No CVE Unauthorized access vulnerability exists in DocuPrint of Fujifilm Commercial Innovation (China) Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
DocuPrint is an all-in-one printer. Fujifilm Business Innovation (China) Co., Ltd. DocuPrint has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2242 No CVE A weak password vulnerability exists in the backend of China Telecom's telecom gateway configuration management CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
China Telecom Group Co., Ltd. was established in September 2000. It is a large-scale state-owned communications enterprise in China and a global partner of the Shanghai World Expo. A weak password vulnerability exists in the backend configuration management of China Telecom's telecom gateway. Attackers can use this vulnerability to log in to the backend to obtain sensitive information.
VAR-202106-2244 No CVE Beijing Digital China Cloud Technology Co., Ltd. DCME-120 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
DCME-120 is a new generation of high-performance Internet egress gateway launched by Beijing Digital China Cloud Information Technology Co., Ltd. using MIPS multi-core high-performance processors to meet the business needs of multiple users, multiple traffic, and multiple business types. Beijing Digital China Cloud Information Technology Co., Ltd. DCME-120 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2048 No CVE Command execution vulnerability exists in RG-RAC200b wireless controller CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage. The RG-RAC200b wireless controller has a command execution vulnerability, which can be exploited by an attacker to gain server control authority.
VAR-202106-2049 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability (CNVD-2021-32403) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2050 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability (CNVD-2021-32409) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2051 No CVE JCG-wireless router has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Yichen Technology Co., Ltd. is a professional manufacturer and operator of network and communication equipment. JCG-wireless router has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2052 No CVE JCG-wireless router has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Yichen Technology Co., Ltd. is a manufacturer and operator of network and communication equipment. JCG-wireless router has an unauthorized access vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2053 No CVE ZTE Corporation ZXV10 W815N has an arbitrary file reading vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXV10 W815N is a wireless router of ZTE Corporation. ZTE Corporation ZXV10 W815N has an arbitrary file reading vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2054 No CVE ZTE Corporation ZXV10 W815N has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXV10 W815N is a wireless router of ZTE Corporation. ZTE Corporation ZXV10 W815N has a weak password vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202106-2055 No CVE ZTE Corporation ZXHN E5500 has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZXHN E5500 is a router of ZTE Corporation. ZTE Corporation ZXHN E5500 has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2056 No CVE RG-EG Easy Gateway web management system has weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services. RG-EG Easy Gateway web management system has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202106-2057 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability (CNVD-2021-32411) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2058 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability (CNVD-2021-32412) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202106-2059 No CVE Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability (CNVD-2021-32413) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
Tenda AC11 is a wireless router that uses RTOS operating system. Shenzhen Jixiang Tengda Technology Co., Ltd. AC 11 has a binary vulnerability, which can be exploited by attackers to cause a denial of service.