VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202104-1182 CVE-2021-27698 RIOT-OS  Buffer Overflow Vulnerability in Linux CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c through the _parse_options() function. RIOT-OS Contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RIOT is a real-time multi-threaded IoT operating system that supports a series of devices commonly found in the Internet of Things. No detailed vulnerability details are currently provided. RIOT-OS 2021.01 has a security vulnerability, which stems from a buffer overflow vulnerability in the parse options() function in sys net gnrc routing rpl gnrc rpl control messages.c
VAR-202104-1018 CVE-2021-27357 RIOT-OS  Buffer Overflow Vulnerability in Linux CVSS V2: 7.5
CVSS V3: 9.8
Severity: CRITICAL
RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c. RIOT-OS Contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RIOT is a real-time multi-threaded IoT operating system that supports a series of devices commonly found in the Internet of Things. No detailed vulnerability details are currently provided
VAR-202104-1362 CVE-2021-28196 ASUS BMC Firmware security feature vulnerability (CNVD-2021-36007) CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China. ASUS BMC firmware Web management page has a security feature vulnerability
VAR-202104-1357 CVE-2021-28191 ASUS BMC Firmware security feature vulnerability (CNVD-2021-31751) CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
The Firmware update function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China
VAR-202104-1359 CVE-2021-28193 ASUS BMC Firmware security feature vulnerability (CNVD-2021-31750) CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China
VAR-202104-1364 CVE-2021-28198 ASUS BMC Firmware security feature vulnerability (CNVD-2021-36008) CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China
VAR-202104-1352 CVE-2021-28201 plural  ASUS  Classic buffer overflow vulnerability in the product CVSS V2: 4.0
CVSS V3: 4.9
Severity: MEDIUM
The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. plural ASUS The product contains a classic buffer overflow vulnerability.Denial of service (DoS) It may be put into a state. ASUS BMC Firmware is a firmware of ASUS Corporation of China
VAR-202104-1134 CVE-2021-25692 Check Point Security Gateway Security hole CVSS V2: 2.1
CVSS V3: 4.6
Severity: MEDIUM
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3
VAR-202104-1996 No CVE Ruijie Networks Co., Ltd. RSR router has an arbitrary file reading vulnerability CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects. Ruijie Networks Co., Ltd. RSR router has an arbitrary file reading vulnerability. Attackers can use this vulnerability to perform arbitrary file reading operations.
VAR-202104-1997 No CVE Ruijie Networks Co., Ltd. RSR router has logic flaws and vulnerabilities CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services. Ruijie Networks Co., Ltd. RSR router has a logic flaw vulnerability. Attackers can use this vulnerability to log in a low-privileged user to vertically override a user with administrator privileges.
VAR-202104-1999 No CVE An arbitrary command execution vulnerability exists in the wireless SmartWeb management system of Ruijie Networks Co., Ltd. CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage. An arbitrary command execution vulnerability exists in the wireless SmartWeb management system of Ruijie Networks. An attacker can use this vulnerability to execute arbitrary commands and obtain user passwords.
VAR-202104-2001 No CVE Ruijie Networks NBR router has logic flaws and vulnerabilities CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects. Ruijie Networks NBR router has a logic flaw vulnerability. Attackers can use this vulnerability to log in a low-privileged user to vertically override a user with administrator privileges.
VAR-202104-2004 No CVE Ruijie Networks NBR router has command execution vulnerabilities CVSS V2: 7.1
CVSS V3: -
Severity: HIGH
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects. Ruijie Networks NBR router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
VAR-202104-2072 No CVE A SQL injection vulnerability exists in the Big Wisdom Fire Digital Monitoring Center platform CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
The Big Wisdom Fire Fighting Digital Monitoring Center Platform is a remote monitoring system for the Internet of Fire Fighting. The system is suitable for smart fire fighting platforms under the new smart city, suitable for urban networking, industry networking, large-scale enterprise networking and remote unattended places. There is a SQL injection vulnerability in the Big Wisdom Fire Digital Monitoring Center platform, which can be used by attackers to obtain sensitive information in the database.
VAR-202104-0059 CVE-2020-17453 plural  WSO2  Product   Cross-site Scripting Vulnerability CVSS V2: 4.3
CVSS V3: 6.1
Severity: MEDIUM
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. plural WSO2 Product Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. WSO2 Management Console is an application software of American WSO2 Company
VAR-202104-0036 CVE-2020-11251 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 9.4
CVSS V3: 9.1
Severity: CRITICAL
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
VAR-202104-0034 CVE-2020-11246 plural  Qualcomm  Product Double Release Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a double release vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202104-0027 CVE-2020-11231 plural  Qualcomm  Product Double Release Vulnerability CVSS V2: 4.6
CVSS V3: 6.7
Severity: MEDIUM
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a double release vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202104-0028 CVE-2020-11234 plural  Qualcomm  Product Free Memory Usage Vulnerability CVSS V2: 7.2
CVSS V3: 7.8
Severity: HIGH
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
VAR-202104-0025 CVE-2020-11191 plural  Qualcomm  Out-of-bounds read vulnerabilities in the product CVSS V2: 9.4
CVSS V3: 9.1
Severity: CRITICAL
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state