VARIoT IoT vulnerabilities database
| VAR-202104-2047 | No CVE | KUKA.OfficeLite has a command execution vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
KUKA.OfficeLite is KUKA's virtual robot controller.
KUKA.OfficeLite has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary code remotely through constructed data.
| VAR-202104-2048 | No CVE | Zhejiang Dahua Technology Co., Ltd. A3A04MG7 has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Zhejiang Dahua Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core.
Zhejiang Dahua Technology Co., Ltd. A3A04MG7 has a denial of service vulnerability. An attacker can use this vulnerability to cause a denial of service.
| VAR-202104-2052 | No CVE | File upload vulnerability exists in KUKA.OfficeLite |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
KUKA.OfficeLite is KUKA's virtual robot controller.
KUKA.OfficeLite has a file upload vulnerability. An attacker can use the vulnerability to upload a webshell to gain server permissions.
| VAR-202104-2065 | No CVE | GX Works2 has a denial of service vulnerability (CNVD-2021-16895) |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
GX Works2 is a PLC programming software.
GX Works2 has an out-of-bounds memory access vulnerability. Attackers can use this vulnerability to cause the program to crash.
| VAR-202104-2066 | No CVE | GX Works2 has an out-of-bounds memory access vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
GX Works2 is a PLC programming software.
GX Works2 has an out-of-bounds memory access vulnerability. Attackers can use this vulnerability to cause the program to crash.
| VAR-202104-2067 | No CVE | EasyBuilder Pro has a denial of service vulnerability (CNVD-2021-16898) |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
EasyBuilder Pro is a configuration software developed by Weilun.
EasyBuilder Pro has a denial of service vulnerability. An attacker can use this vulnerability to cause the process to fall into an endless loop, resulting in a denial of service.
| VAR-202104-2068 | No CVE | EasyBuilder Pro has a stack overflow vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
EasyBuilder Pro is a configuration software developed by Weilun.
EasyBuilder Pro has a stack overflow vulnerability. Attackers can use this vulnerability to cause the program to crash.
| VAR-202104-2069 | No CVE | EasyBuilder Pro has a buffer overflow vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
EasyBuilder Pro is a configuration software developed by Weilun.
EasyBuilder Pro has a buffer overflow vulnerability. Attackers can use this vulnerability to cause the program to crash.
| VAR-202104-2070 | No CVE | GX Works2 has a code injection vulnerability |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
GX Works2 is a PLC programming software.
GX Works2 has a code injection vulnerability. An attacker can use this vulnerability to gain server permissions.
| VAR-202104-2031 | No CVE | ZTE Corporation IAD 16FXS has a weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
ZTE Corporation is the world's leading provider of integrated communications solutions.
ZTE Corporation IAD 16FXS has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202104-2032 | No CVE | Unauthorized access vulnerability exists in the MAS mobile proxy server of China Mobile Communications Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
MAS mobile proxy server is an access tool that assists enterprises in realizing wireless applications in their original business systems.
The MAS mobile proxy server of China Mobile Communications Co., Ltd. has an unauthorized access vulnerability. Attackers can use this vulnerability to access the background control interface and restart the device.
| VAR-202104-0754 | CVE-2021-20020 | SonicWall GMS Authentication vulnerabilities in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root. SonicWall GMS Contains an authentication vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Pillow is a Python-based image processing library.
There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. Sonicwall SonicWall Global Management System (GMS) is a set of global management system of American SonicWall (Sonicwall) company. The system enables rapid deployment and centralized management of Dell SonicWALL firewall, anti-spam, backup and recovery, and secure remote access solutions
| VAR-202104-2049 | CVE-2020-9211 | Huawei of Mate 30 Out-of-bounds read vulnerability in firmware |
CVSS V2: 6.2 CVSS V3: 6.4 Severity: MEDIUM |
There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103)
This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211. Huawei of Mate 30 The firmware contains out-of-bounds read and out-of-bounds write vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei Mate 30 is a smart phone of China's Huawei (Huawei) company
| VAR-202104-2034 | No CVE | HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 have weak password vulnerabilities |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 are feature-rich and easy-to-use IP phones.
HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 have a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
| VAR-202104-2035 | No CVE | A directory traversal vulnerability exists in the video encoding device access gateway of Hangzhou Hikvision System Technology Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions.
Hangzhou Hikvision System Technology Co., Ltd. video encoding device access gateway has a directory traversal vulnerability. Attackers can use this vulnerability to traverse all directories and files of the device to obtain sensitive information.
| VAR-202104-2036 | No CVE | Any file reading vulnerability exists in the access network of Hangzhou Hikvision System Technology Co., Ltd. video encoding equipment |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions.
The video encoding equipment access network of Hangzhou Hikvision System Technology Co., Ltd. has an arbitrary file reading vulnerability. Attackers can use this vulnerability to read all files to obtain sensitive information.
| VAR-202104-2037 | No CVE | An unauthorized access vulnerability exists in the access gateway of the video encoding equipment of Hangzhou Hikvision System Technology Co., Ltd. |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions.
Hangzhou Hikvision System Technology Co., Ltd. video encoding equipment access gateway has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
| VAR-202104-2038 | No CVE | H8922 4G wireless router has a denial of service vulnerability |
CVSS V2: 6.1 CVSS V3: - Severity: MEDIUM |
Shenzhen Hongdian Technology Co., Ltd. H8922 supports dual SIM card backup; built-in WiFi module, supports wired and wireless, wireless and wireless mutual backup; richer interfaces, stronger scalability (4 LAN ports, 1 WAN port); It is an industrial-grade VPN router with rich functions and a wide range of applications.
The H8922 4G wireless router has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
| VAR-202104-2039 | No CVE | Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda router has unauthorized access vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment.
Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda router has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
| VAR-202104-2040 | No CVE | Shanghai Aitai Technology Co., Ltd. aggressive 750W has a command execution vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Shanghai Aitai Technology Co., Ltd. enterprising 750W is an enterprise-class wireless router.
Shanghai Aitai Technology Co., Ltd. enterprising 750W has a command execution vulnerability. Attackers can use this vulnerability to gain control of the website server.