Show filters
296 Total Results
Displaying 111-120 of 296
Sort by:
Attacker Value
Unknown

CVE-2020-6993

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to sensitive information from the web service without authorization.
Attacker Value
Unknown

CVE-2020-6985

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console.
Attacker Value
Unknown

CVE-2020-6995

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.
Attacker Value
Unknown

CVE-2020-6983

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.
Attacker Value
Unknown

CVE-2020-6987

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.
Attacker Value
Unknown

CVE-2020-6989

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows remote attackers to cause a denial-of-service condition or execute arbitrary code.
Attacker Value
Unknown

CVE-2020-7003

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.
Attacker Value
Unknown

CVE-2019-18242

Disclosure Date: March 24, 2020 (last updated February 21, 2025)
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.
Attacker Value
Unknown

CVE-2019-9101

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and the server.
Attacker Value
Unknown

CVE-2019-9097

Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A high rate of transit traffic may cause a low-memory condition and a denial of service.