VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-202104-2047 No CVE KUKA.OfficeLite has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
KUKA.OfficeLite is KUKA's virtual robot controller. KUKA.OfficeLite has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary code remotely through constructed data.
VAR-202104-2048 No CVE Zhejiang Dahua Technology Co., Ltd. A3A04MG7 has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Zhejiang Dahua Technology Co., Ltd. is a smart IoT solution provider and operation service provider with video as the core. Zhejiang Dahua Technology Co., Ltd. A3A04MG7 has a denial of service vulnerability. An attacker can use this vulnerability to cause a denial of service.
VAR-202104-2052 No CVE File upload vulnerability exists in KUKA.OfficeLite CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
KUKA.OfficeLite is KUKA's virtual robot controller. KUKA.OfficeLite has a file upload vulnerability. An attacker can use the vulnerability to upload a webshell to gain server permissions.
VAR-202104-2065 No CVE GX Works2 has a denial of service vulnerability (CNVD-2021-16895) CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
GX Works2 is a PLC programming software. GX Works2 has an out-of-bounds memory access vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202104-2066 No CVE GX Works2 has an out-of-bounds memory access vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
GX Works2 is a PLC programming software. GX Works2 has an out-of-bounds memory access vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202104-2067 No CVE EasyBuilder Pro has a denial of service vulnerability (CNVD-2021-16898) CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
EasyBuilder Pro is a configuration software developed by Weilun. EasyBuilder Pro has a denial of service vulnerability. An attacker can use this vulnerability to cause the process to fall into an endless loop, resulting in a denial of service.
VAR-202104-2068 No CVE EasyBuilder Pro has a stack overflow vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
EasyBuilder Pro is a configuration software developed by Weilun. EasyBuilder Pro has a stack overflow vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202104-2069 No CVE EasyBuilder Pro has a buffer overflow vulnerability CVSS V2: 4.9
CVSS V3: -
Severity: MEDIUM
EasyBuilder Pro is a configuration software developed by Weilun. EasyBuilder Pro has a buffer overflow vulnerability. Attackers can use this vulnerability to cause the program to crash.
VAR-202104-2070 No CVE GX Works2 has a code injection vulnerability CVSS V2: 8.3
CVSS V3: -
Severity: HIGH
GX Works2 is a PLC programming software. GX Works2 has a code injection vulnerability. An attacker can use this vulnerability to gain server permissions.
VAR-202104-2031 No CVE ZTE Corporation IAD 16FXS has a weak password vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
ZTE Corporation is the world's leading provider of integrated communications solutions. ZTE Corporation IAD 16FXS has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
VAR-202104-2032 No CVE Unauthorized access vulnerability exists in the MAS mobile proxy server of China Mobile Communications Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
MAS mobile proxy server is an access tool that assists enterprises in realizing wireless applications in their original business systems. The MAS mobile proxy server of China Mobile Communications Co., Ltd. has an unauthorized access vulnerability. Attackers can use this vulnerability to access the background control interface and restart the device.
VAR-202104-0754 CVE-2021-20020 SonicWall GMS  Authentication vulnerabilities in CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root. SonicWall GMS Contains an authentication vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Pillow is a Python-based image processing library. There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. Sonicwall SonicWall Global Management System (GMS) is a set of global management system of American SonicWall (Sonicwall) company. The system enables rapid deployment and centralized management of Dell SonicWALL firewall, anti-spam, backup and recovery, and secure remote access solutions
VAR-202104-2049 CVE-2020-9211 Huawei  of  Mate 30  Out-of-bounds read vulnerability in firmware CVSS V2: 6.2
CVSS V3: 6.4
Severity: MEDIUM
There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211. Huawei of Mate 30 The firmware contains out-of-bounds read and out-of-bounds write vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Huawei Mate 30 is a smart phone of China's Huawei (Huawei) company
VAR-202104-2034 No CVE HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 have weak password vulnerabilities CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 are feature-rich and easy-to-use IP phones. HUAWEI IP PHONE 7960 and HUAWEI IP ESPACE 7910 have a weak password vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202104-2035 No CVE A directory traversal vulnerability exists in the video encoding device access gateway of Hangzhou Hikvision System Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions. Hangzhou Hikvision System Technology Co., Ltd. video encoding device access gateway has a directory traversal vulnerability. Attackers can use this vulnerability to traverse all directories and files of the device to obtain sensitive information.
VAR-202104-2036 No CVE Any file reading vulnerability exists in the access network of Hangzhou Hikvision System Technology Co., Ltd. video encoding equipment CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions. The video encoding equipment access network of Hangzhou Hikvision System Technology Co., Ltd. has an arbitrary file reading vulnerability. Attackers can use this vulnerability to read all files to obtain sensitive information.
VAR-202104-2037 No CVE An unauthorized access vulnerability exists in the access gateway of the video encoding equipment of Hangzhou Hikvision System Technology Co., Ltd. CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hangzhou Hikvision System Technology Co., Ltd. is a provider of security products and industry solutions. Hangzhou Hikvision System Technology Co., Ltd. video encoding equipment access gateway has an unauthorized access vulnerability. Attackers can use this vulnerability to obtain sensitive information.
VAR-202104-2038 No CVE H8922 4G wireless router has a denial of service vulnerability CVSS V2: 6.1
CVSS V3: -
Severity: MEDIUM
Shenzhen Hongdian Technology Co., Ltd. H8922 supports dual SIM card backup; built-in WiFi module, supports wired and wireless, wireless and wireless mutual backup; richer interfaces, stronger scalability (4 LAN ports, 1 WAN port); It is an industrial-grade VPN router with rich functions and a wide range of applications. The H8922 4G wireless router has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.
VAR-202104-2039 No CVE Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda router has unauthorized access vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shenzhen Jixiang Tengda Technology Co., Ltd. is a high-tech enterprise integrating independent research and development, production and sales of network equipment. Shenzhen Jixiang Tenda Technology Co., Ltd. Tenda router has an unauthorized access vulnerability. Attackers can use the vulnerability to obtain sensitive information.
VAR-202104-2040 No CVE Shanghai Aitai Technology Co., Ltd. aggressive 750W has a command execution vulnerability CVSS V2: 10.0
CVSS V3: -
Severity: HIGH
Shanghai Aitai Technology Co., Ltd. enterprising 750W is an enterprise-class wireless router. Shanghai Aitai Technology Co., Ltd. enterprising 750W has a command execution vulnerability. Attackers can use this vulnerability to gain control of the website server.