Show filters
296 Total Results
Displaying 141-150 of 296
Sort by:
Attacker Value
Unknown

CVE-2020-8858

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9552.
Attacker Value
Unknown

CVE-2019-19707

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.
Attacker Value
Unknown

CVE-2019-10963

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
Attacker Value
Unknown

CVE-2019-10969

Disclosure Date: October 08, 2019 (last updated November 27, 2024)
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.
Attacker Value
Unknown

CVE-2018-11425

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424.
0
Attacker Value
Unknown

CVE-2018-11421

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. The protocol is vulnerable to remote unauthenticated disclosure of sensitive information, including the administrator's password. Under certain conditions, it's also possible to retrieve additional information, such as content of HTTP requests to the device, or the previously used password, due to memory leakages.
0
Attacker Value
Unknown

CVE-2018-11424

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11425.
0
Attacker Value
Unknown

CVE-2018-11422

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. Any commands (including device reboot, configuration download or upload, or firmware upgrade) are accepted and executed by the device without authentication.
0
Attacker Value
Unknown

CVE-2018-11423

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.
0
Attacker Value
Unknown

CVE-2018-11420

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
There is Memory corruption in the web interface of Moxa OnCell G3100-HSPA Series version 1.5 Build 17042015 and prio,r a different vulnerability than CVE-2018-11423.
0