VARIoT IoT vulnerabilities database
| VAR-202104-1359 | CVE-2021-28193 | ASUS BMC Firmware security feature vulnerability (CNVD-2021-31750) |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
The SMTP configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China
| VAR-202104-1364 | CVE-2021-28198 | ASUS BMC Firmware security feature vulnerability (CNVD-2021-36008) |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. ASUS BMC Firmware is a firmware of ASUS Corporation of China
| VAR-202104-1352 | CVE-2021-28201 | plural ASUS Classic buffer overflow vulnerability in the product |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service. plural ASUS The product contains a classic buffer overflow vulnerability.Denial of service (DoS) It may be put into a state. ASUS BMC Firmware is a firmware of ASUS Corporation of China
| VAR-202104-1134 | CVE-2021-25692 | Check Point Security Gateway Security hole |
CVSS V2: 2.1 CVSS V3: 4.6 Severity: MEDIUM |
Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway prior to version 21.01.3
| VAR-202104-1996 | No CVE | Ruijie Networks Co., Ltd. RSR router has an arbitrary file reading vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects.
Ruijie Networks Co., Ltd. RSR router has an arbitrary file reading vulnerability. Attackers can use this vulnerability to perform arbitrary file reading operations.
| VAR-202104-1997 | No CVE | Ruijie Networks Co., Ltd. RSR router has logic flaws and vulnerabilities |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services.
Ruijie Networks Co., Ltd. RSR router has a logic flaw vulnerability. Attackers can use this vulnerability to log in a low-privileged user to vertically override a user with administrator privileges.
| VAR-202104-1999 | No CVE | An arbitrary command execution vulnerability exists in the wireless SmartWeb management system of Ruijie Networks Co., Ltd. |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks Co., Ltd. is a professional network manufacturer with a full range of network equipment product lines and solutions including switches, routers, software, security firewalls, wireless products, and storage.
An arbitrary command execution vulnerability exists in the wireless SmartWeb management system of Ruijie Networks. An attacker can use this vulnerability to execute arbitrary commands and obtain user passwords.
| VAR-202104-2001 | No CVE | Ruijie Networks NBR router has logic flaws and vulnerabilities |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects.
Ruijie Networks NBR router has a logic flaw vulnerability. Attackers can use this vulnerability to log in a low-privileged user to vertically override a user with administrator privileges.
| VAR-202104-2004 | No CVE | Ruijie Networks NBR router has command execution vulnerabilities |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Ruijie Networks Co., Ltd. is a company mainly engaged in information system integration services; Internet virtual private network services; Internet management services and other projects.
Ruijie Networks NBR router has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands.
| VAR-202104-2072 | No CVE | A SQL injection vulnerability exists in the Big Wisdom Fire Digital Monitoring Center platform |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
The Big Wisdom Fire Fighting Digital Monitoring Center Platform is a remote monitoring system for the Internet of Fire Fighting. The system is suitable for smart fire fighting platforms under the new smart city, suitable for urban networking, industry networking, large-scale enterprise networking and remote unattended places.
There is a SQL injection vulnerability in the Big Wisdom Fire Digital Monitoring Center platform, which can be used by attackers to obtain sensitive information in the database.
| VAR-202104-0059 | CVE-2020-17453 | plural WSO2 Product Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
WSO2 Management Console through 5.10 allows XSS via the carbon/admin/login.jsp msgId parameter. plural WSO2 Product Contains a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. WSO2 Management Console is an application software of American WSO2 Company
| VAR-202104-0036 | CVE-2020-11251 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 9.4 CVSS V3: 9.1 Severity: CRITICAL |
Out-of-bounds read vulnerability while accessing DTMF payload due to lack of check of buffer length before copying in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202104-0034 | CVE-2020-11246 | plural Qualcomm Product Double Release Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a double release vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202104-0027 | CVE-2020-11231 | plural Qualcomm Product Double Release Vulnerability |
CVSS V2: 4.6 CVSS V3: 6.7 Severity: MEDIUM |
Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile. plural Qualcomm The product contains a double release vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202104-0028 | CVE-2020-11234 | plural Qualcomm Product Free Memory Usage Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
When sending a socket event message to a user application, invalid information will be passed if socket is freed by other thread resulting in a Use After Free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability related to the use of freed memory.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state
| VAR-202104-0025 | CVE-2020-11191 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 9.4 CVSS V3: 9.1 Severity: CRITICAL |
Out of bound read occurs while processing crafted SDP due to lack of check of null string in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202104-0035 | CVE-2020-11247 | plural Qualcomm Out-of-bounds read vulnerabilities in the product |
CVSS V2: 9.4 CVSS V3: 9.1 Severity: CRITICAL |
Out of bound memory read while unpacking data due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an out-of-bounds read vulnerability.Information is obtained and denial of service (DoS) It may be put into a state
| VAR-202104-0038 | CVE-2020-11255 | plural Qualcomm Product vulnerabilities to lack of memory release after expiration |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables. plural Qualcomm The product contains a vulnerability regarding the lack of free memory after expiration.Denial of service (DoS) It may be put into a state
| VAR-202104-1112 | CVE-2021-30055 | Knowage Suite In SQL Injection vulnerability |
CVSS V2: 6.5 CVSS V3: 8.8 Severity: HIGH |
A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report
| VAR-202104-1115 | CVE-2021-30058 | Knowage Suite Cross-site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST' parameter