VARIoT IoT vulnerabilities database
| VAR-202102-0548 | CVE-2021-1372 | Cisco Webex Meetings Desktop Application and Windows for Webex Productivity Tools Vulnerability in leaking important information from data queries in |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticated, local attacker to gain access to sensitive information on an affected system. This vulnerability is due to the unsafe usage of shared memory by the affected software. An attacker with permissions to view system memory could exploit this vulnerability by running an application on the local system that is designed to read shared memory. A successful exploit could allow the attacker to retrieve sensitive information from the shared memory, including usernames, meeting information, or authentication tokens. Note: To exploit this vulnerability, an attacker must have valid credentials on a Microsoft Windows end-user system and must log in after another user has already authenticated with Webex on the same end-user system. There is no information about this vulnerability at present. Please keep an eye on CNNVD or vendor announcements
| VAR-202102-0544 | CVE-2021-1366 | Windows for Cisco AnyConnect Secure Mobility Client Digital Signature Verification Vulnerability in |
CVSS V2: 6.9 CVSS V3: 7.8 Severity: HIGH |
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. Windows for Cisco AnyConnect Secure Mobility Client Exists in a digital signature validation vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Cisco AnyConnect Secure Mobility Client. There is no information about this vulnerability at present. Please keep an eye on CNNVD or vendor announcements
| VAR-202102-0264 | CVE-2020-24462 | Intel(R) Graphics Driver Out-of-bounds Vulnerability in Microsoft |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Out of bounds write in the Intel(R) Graphics Driver before version 15.33.53.5161, 15.36.40.5162, 15.40.47.5166, 15.45.33.5164 and 27.20.100.8336 may allow an authenticated user to potentially enable an escalation of privilege via local access. Intel(R) Graphics Driver Is vulnerable to an out-of-bounds write.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in the Intel Graphics Driver. There is no information about this vulnerability at present. Please keep an eye on CNNVD or the manufacturer's announcement
| VAR-202102-0068 | CVE-2020-12362 | Windows and Linux for Intel(R) Graphics Drivers Integer overflow vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time. 6 ELS) - i386, s390x, x86_64
3. Summary:
Red Hat OpenShift Container Platform release 4.7.13 is now available with
updates to packages and images that fix several bugs. Description:
Red Hat OpenShift Container Platform is Red Hat's cloud computing
Kubernetes application platform solution designed for on-premise or private
cloud deployments.
This advisory contains the container images for Red Hat OpenShift Container
Platform 4.7.13. See the following advisory for the RPM packages for this
release:
https://access.redhat.com/errata/RHSA-2021:2122
Space precludes documenting all of the container images in this advisory.
See the following Release Notes documentation, which will be updated
shortly for this release, for details about these changes:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel
ease-notes.html
This update fixes the following bug among others:
* Previously, resources for the ClusterOperator were being created early in
the update process, which led to update failures when the ClusterOperator
had no status condition while Operators were updating. This bug fix changes
the timing of when these resources are created. As a result, updates can
take place without errors. (BZ#1959238)
Security Fix(es):
* gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index
validation (CVE-2021-3121)
You may download the oc tool and use it to inspect release image metadata
as follows:
(For x86_64 architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-x86_64
The image digest is
sha256:783a2c963f35ccab38e82e6a8c7fa954c3a4551e07d2f43c06098828dd986ed4
(For s390x architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-s390x
The image digest is
sha256:4cf44e68413acad063203e1ee8982fd01d8b9c1f8643a5b31cd7ff341b3199cd
(For ppc64le architecture)
$ oc adm release info
quay.io/openshift-release-dev/ocp-release:4.7.13-ppc64le
The image digest is
sha256:d47ce972f87f14f1f3c5d50428d2255d1256dae3f45c938ace88547478643e36
All OpenShift Container Platform 4.7 users are advised to upgrade to these
updated packages and images when they are available in the appropriate
release channel. To check for available updates, use the OpenShift Console
or the CLI oc command. Instructions for upgrading a cluster are available
at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- -between-minor.html#understanding-upgrade-channels_updating-cluster-between
- -minor
3. Solution:
For OpenShift Container Platform 4.7 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this asynchronous errata update:
https://docs.openshift.com/container-platform/4.7/release_notes/ocp-4-7-rel
ease-notes.html
Details on how to access this content are available at
https://docs.openshift.com/container-platform/4.7/updating/updating-cluster
- -cli.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
1923268 - [Assisted-4.7] [Staging] Using two both spelling "canceled" "cancelled"
1947216 - [AWS] Missing iam:ListAttachedRolePolicies permission in permissions.go
1953963 - Enable/Disable host operations returns cluster resource with incomplete hosts list
1957749 - ovn-kubernetes pod should have CPU and memory requests set but not limits
1959238 - CVO creating cloud-controller-manager too early causing upgrade failures
1960103 - SR-IOV obliviously reboot the node
1961941 - Local Storage Operator using LocalVolume CR fails to create PV's when backend storage failure is simulated
1962302 - packageserver clusteroperator does not set reason or message for Available condition
1962312 - Deployment considered unhealthy despite being available and at latest generation
1962435 - Public DNS records were not deleted when destroying a cluster which is using byo private hosted zone
1963115 - Test verify /run filesystem contents failing
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security update
Advisory ID: RHSA-2021:2164-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:2164
Issue date: 2021-06-01
CVE Names: CVE-2019-19532 CVE-2020-12362 CVE-2020-25211
CVE-2020-25705 CVE-2020-29661
=====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 7.4
Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update
Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP
Solutions.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Server AUS (v. 7.4) - noarch, x86_64
Red Hat Enterprise Linux Server E4S (v. 7.4) - noarch, ppc64le, x86_64
Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64
Red Hat Enterprise Linux Server Optional E4S (v. 7.4) - ppc64le, x86_64
Red Hat Enterprise Linux Server Optional TUS (v. 7.4) - x86_64
Red Hat Enterprise Linux Server TUS (v. 7.4) - noarch, x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
Security Fix(es):
* kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)
* kernel: Local buffer overflow in ctnetlink_parse_tuple_filter in
net/netfilter/nf_conntrack_netlink.c (CVE-2020-25211)
* kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an
use-after-free (CVE-2020-29661)
* kernel: malicious USB devices can lead to multiple out-of-bounds write
(CVE-2019-19532)
* kernel: ICMP rate limiting can be used for DNS poisoning attack
(CVE-2020-25705)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1781821 - CVE-2019-19532 kernel: malicious USB devices can lead to multiple out-of-bounds write
1877571 - CVE-2020-25211 kernel: Local buffer overflow in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c
1894579 - CVE-2020-25705 kernel: ICMP rate limiting can be used for DNS poisoning attack
1906525 - CVE-2020-29661 kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free
1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers
6. Package List:
Red Hat Enterprise Linux Server AUS (v. 7.4):
Source:
kernel-3.10.0-693.87.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-693.87.1.el7.noarch.rpm
kernel-doc-3.10.0-693.87.1.el7.noarch.rpm
x86_64:
kernel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-headers-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-693.87.1.el7.x86_64.rpm
perf-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server E4S (v. 7.4):
Source:
kernel-3.10.0-693.87.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-693.87.1.el7.noarch.rpm
kernel-doc-3.10.0-693.87.1.el7.noarch.rpm
ppc64le:
kernel-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debug-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-devel-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-headers-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-tools-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-693.87.1.el7.ppc64le.rpm
perf-3.10.0-693.87.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
python-perf-3.10.0-693.87.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
x86_64:
kernel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-headers-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-693.87.1.el7.x86_64.rpm
perf-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server TUS (v. 7.4):
Source:
kernel-3.10.0-693.87.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-693.87.1.el7.noarch.rpm
kernel-doc-3.10.0-693.87.1.el7.noarch.rpm
x86_64:
kernel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-devel-3.10.0-693.87.1.el7.x86_64.rpm
kernel-headers-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-693.87.1.el7.x86_64.rpm
perf-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional AUS (v. 7.4):
x86_64:
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional E4S (v. 7.4):
ppc64le:
kernel-debug-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-693.87.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.ppc64le.rpm
x86_64:
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional TUS (v. 7.4):
x86_64:
kernel-debug-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-693.87.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-693.87.1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2019-19532
https://access.redhat.com/security/cve/CVE-2020-12362
https://access.redhat.com/security/cve/CVE-2020-25211
https://access.redhat.com/security/cve/CVE-2020-25705
https://access.redhat.com/security/cve/CVE-2020-29661
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYLXzYtzjgjWX9erEAQjW3A//ax5IBIju/37C2l6J5HuZYu5UyI9yyTpC
KTB7FRWm+o/Ppr+YR4Tb8WuWtAJwRJgGAIM5jDP+NTHR+PzIua6ei+JtT4nx/1K/
lsylgQDkku4K1ZC9R+235Gj56TKee660vXZ80qWT/M62WkNprdS4XbD01HCAITL0
j1/7cCCSFJfPEUbKGAjk6IgEQrcCo01mrms7Ke6nuqsjKV9JOr6mB8Z+xD5yibg9
23Zkd28mMNgrdzABKuGckrwgucJCGcM34Y0ZVc2fAspk15ei+ELTut4x/fu6Xiqu
ZaCB0lR4DmVQpa2tcuqO2iIqgNcYoPxzuMSoyD7DHx0MEbIrXtyYI5YIAmgHeHGg
tce2dVFP5UnmW6Zss2kwj4uqh6w/eHrwESdPMbNzsCMj5lV2/TDXDqEwoqaJNNzw
kHDjo6+eADy3wavMzRhl2J1kHABCNmwCVn86GC+jyhQ4XObc/oAqkwiF3kLPP7K5
3UROKYWXT6Xy1JGeADaw+Bv7ME772PyKXLN0yFTIgFag/ECwT76OTHbCqwVk0DJJ
72ILUIXscEZ+wwmFULoVZ2D6+1o/+UnttlvsAf3EIme/xLjuOC1wxD4MuR+ypVDn
6dKxgmkR7uL9r/OBrTEQbYAbI3ALAu5B2wSlAxl7Jel606Sd2/iKmFgToZSFEsDC
iRLouwDKWC8=
=l4Zb
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. Bugs fixed (https://bugzilla.redhat.com/):
1921650 - CVE-2021-3121 gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation
5. JIRA issues fixed (https://issues.jboss.org/):
LOG-1328 - Port fix to 5.0.z for BZ-1945168
6.
Bug Fix(es):
* memcg: mem_cgroup_idr can be updated in an uncoordinated manner which can
lead to corruption (BZ#1931901)
* Kernel experiences panic in update_group_power() due to division error
even with Bug 1701115 fix (BZ#1961624)
4. 8.2) - x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Bug Fix(es):
* kernel-rt: update RT source tree to the latest RHEL-8.2.z9 Batch source
tree (BZ#1949685)
4. 8.2) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Bug Fix(es):
* RHEL8.3 - Include patch: powerpc/pci: Remove LSI mappings on device
teardown (xive/pci) (BZ#1931925)
* RHEL8.2 - [P10][Denali] System crash during a perf sanity test (perf:)
(BZ#1933995)
* [RHEL 8.1] AMD/EPYC nested guest virtualization L1 guest crash
(BZ#1945404)
* [HPEMC 8.1 REGRESSION] skx_uncore: probe of 0008:80:08.0 failed with
error -22 (BZ#1947114)
* iperf3 over geneve created on vlan would fail (BZ#1947979)
* [Azure][RHEL-8]Mellanox Patches To Prevent Kernel Hang In MLX4
(BZ#1952071)
* [HPEMC 8.4 REGRESSION]: perf/x86/intel/uncore kernel panic vulnerability
on Haswell and Broadwell servers (BZ#1956685)
4
| VAR-202102-0680 | CVE-2020-7848 | EFM ipTIME C200 IP Camera Command injection vulnerability |
CVSS V2: 7.7 CVSS V3: 8.0 Severity: HIGH |
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value
| VAR-202102-0496 | CVE-2021-20655 | FileZen OS command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 7.2 Severity: HIGH |
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. FileZen is a device for secure file transfer and sharing via email or web interface.
FileZen 3.0.0-4.2.7, 5.0.0-5.0.2 have OS command injection vulnerabilities
| VAR-202102-0020 | CVE-2020-13550 | Advantech WebAccess/SCADA Traversal Vulnerability in Japan |
CVSS V2: 4.0 CVSS V3: 7.7 Severity: HIGH |
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability. Advantech WebAccess/SCADA Contains a path traversal vulnerability.Information may be obtained. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment. There is a path traversal vulnerability in Advantech WebAccess/SCADA, which originates from the failure of network systems or products to properly filter resources or special elements in file paths. An attacker could exploit this vulnerability to access locations outside of restricted directories
| VAR-202102-0021 | CVE-2020-13551 | Advantech WebAccess/SCADA Vulnerability in privilege management |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. Advantech WebAccess/SCADA Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment
| VAR-202102-0904 | CVE-2021-20071 | Racom's MIDGE Firmware Cross-site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the sms.php dialogs. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. Attackers can use this vulnerability to execute javascript code through sms.php
| VAR-202102-0908 | CVE-2021-20075 | Racom's MIDGE Firmware Vulnerability in privilege management |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd. Racom's MIDGE Firmware Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. Attackers can use this vulnerability to elevate permissions through configd
| VAR-202102-0906 | CVE-2021-20073 | Racom MIDGE Cross-site request forgery vulnerability in firmware |
CVSS V2: 6.8 CVSS V3: 8.8 Severity: HIGH |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries. Racom MIDGE A cross-site request forgery vulnerability exists in the firmware.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. No detailed vulnerability details are currently provided
| VAR-202102-0907 | CVE-2021-20074 | Racom MIDGE In firmware OS Command injection vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands. Racom MIDGE For firmware, OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. Attackers can use this vulnerability to execute arbitrary OS commands
| VAR-202102-0905 | CVE-2021-20072 | Racom MIDGE Privilege management vulnerabilities in firmware |
CVSS V2: 8.7 CVSS V3: 7.2 Severity: HIGH |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral. Racom MIDGE There is a permission management vulnerability in the firmware.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications.
RACOM M!DGE version 4.4.40.105 firmware has a directory traversal vulnerability
| VAR-202102-0901 | CVE-2021-20068 | Racom's MIDGE Firmware Cross-site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the error handling functionality of web pages. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications
| VAR-202102-0902 | CVE-2021-20069 | Racom's MIDGE Firmware Cross-site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via the regionalSettings.php dialogs. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. Attackers can use this vulnerability to execute JavaScript code through regionalSettings.php
| VAR-202102-0023 | CVE-2020-13553 | Advantech WebAccess/SCADA Vulnerability in privilege management |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. Advantech WebAccess/SCADA Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment
| VAR-202102-0022 | CVE-2020-13552 | Advantech WebAccess/SCADA Vulnerability in privilege management |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. Advantech WebAccess/SCADA Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment
| VAR-202102-0024 | CVE-2020-13555 | Advantech WebAccess/SCADA Vulnerability in privilege management |
CVSS V2: 7.2 CVSS V3: 8.8 Severity: HIGH |
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. Advantech WebAccess/SCADA Contains a privilege management vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment
| VAR-202102-0903 | CVE-2021-20070 | Racom's MIDGE Firmware Cross-site Scripting Vulnerability |
CVSS V2: 3.5 CVSS V3: 4.8 Severity: MEDIUM |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the virtualization.php dialogs. RACOM M!DGE is a cellular router designed for mission-critical applications such as SCADA and telemetry, and is very suitable for many different wireless applications. Attackers can use this vulnerability to execute JavaScript code through virtualization.php
| VAR-202103-0009 | CVE-2020-13554 | Advantech WebAccess/SCADA Inappropriate Default Permission Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. Advantech WebAccess/SCADA Is vulnerable to incorrect default permissions.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. Advantech WebAccess/SCADA is a set of SCADA software based on browser architecture of Advantech. The software supports dynamic graphic display and real-time data control, and provides functions for remote control and management of automation equipment