Show filters
296 Total Results
Displaying 11-20 of 296
Sort by:
Attacker Value
Unknown

CVE-2024-9137

Disclosure Date: October 14, 2024 (last updated January 17, 2025)
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.
0
Attacker Value
Unknown

CVE-2024-6787

Disclosure Date: September 21, 2024 (last updated October 01, 2024)
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious code and potentially cause file losses.
Attacker Value
Unknown

CVE-2024-6786

Disclosure Date: September 21, 2024 (last updated October 01, 2024)
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
Attacker Value
Unknown

CVE-2024-6785

Disclosure Date: September 21, 2024 (last updated September 28, 2024)
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
Attacker Value
Unknown

CVE-2024-4641

Disclosure Date: June 25, 2024 (last updated September 19, 2024)
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
Attacker Value
Unknown

CVE-2024-4640

Disclosure Date: June 25, 2024 (last updated September 19, 2024)
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash.
Attacker Value
Unknown

CVE-2024-4639

Disclosure Date: June 25, 2024 (last updated September 19, 2024)
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Attacker Value
Unknown

CVE-2024-4638

Disclosure Date: June 25, 2024 (last updated September 25, 2024)
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Attacker Value
Unknown

CVE-2024-3576

Disclosure Date: May 06, 2024 (last updated May 07, 2024)
The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing user-controllable input before placing it in output. Malicious users may use the vulnerability to get sensitive information and escalate privileges.
0
Attacker Value
Unknown

CVE-2024-1220

Disclosure Date: March 06, 2024 (last updated March 06, 2024)
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.
0