Show filters
296 Total Results
Displaying 121-130 of 296
Sort by:
Attacker Value
Unknown
CVE-2019-9095
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administrative access.
0
Attacker Value
Unknown
CVE-2019-9103
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in WEB-service without authorization.
0
Attacker Value
Unknown
CVE-2019-9098
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.
0
Attacker Value
Unknown
CVE-2019-9104
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.
0
Attacker Value
Unknown
CVE-2019-9102
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.
0
Attacker Value
Unknown
CVE-2019-9099
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).
0
Attacker Value
Unknown
CVE-2019-9096
Disclosure Date: March 11, 2020 (last updated February 21, 2025)
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords.
0
Attacker Value
Unknown
CVE-2019-18238
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.
0
Attacker Value
Unknown
CVE-2019-5137
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
0
Attacker Value
Unknown
CVE-2019-5140
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the device. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
0