Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2020-13537

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality and among them the mosquitto executable is also run.
Attacker Value
Unknown

CVE-2020-13536

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.
Attacker Value
Unknown

CVE-2018-7506

Disclosure Date: April 06, 2018 (last updated November 26, 2024)
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
0
Attacker Value
Unknown

CVE-2017-14030

Disclosure Date: January 12, 2018 (last updated November 26, 2024)
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
0
Attacker Value
Unknown

CVE-2017-7455

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
0
Attacker Value
Unknown

CVE-2017-7456

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
0