Show filters
296 Total Results
Displaying 221-230 of 296
Sort by:
Attacker Value
Unknown
CVE-2017-13700
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
0
Attacker Value
Unknown
CVE-2017-13703
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.
0
Attacker Value
Unknown
CVE-2017-13702
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.
0
Attacker Value
Unknown
CVE-2017-14028
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exhaust memory resources by sending a large amount of TCP SYN packets.
0
Attacker Value
Unknown
CVE-2017-16715
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exploit a flaw in the handling of Ethernet frame padding that may allow for information exposure.
0
Attacker Value
Unknown
CVE-2017-16719
Disclosure Date: November 16, 2017 (last updated November 26, 2024)
An Injection issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to inject packets that could potentially disrupt the availability of the device.
0
Attacker Value
Unknown
CVE-2017-7915
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. An attacker can freely use brute force to determine parameters needed to bypass authentication.
0
Attacker Value
Unknown
CVE-2017-7913
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application's configuration file contains parameters that represent passwords in plaintext.
0
Attacker Value
Unknown
CVE-2017-7917
Disclosure Date: May 29, 2017 (last updated November 26, 2024)
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
0
Attacker Value
Unknown
CVE-2016-8721
Disclosure Date: April 20, 2017 (last updated November 26, 2024)
An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.
0