Show filters
296 Total Results
Displaying 51-60 of 296
Sort by:
Attacker Value
Unknown
CVE-2023-33235
Disclosure Date: May 22, 2023 (last updated October 08, 2023)
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
0
Attacker Value
Unknown
CVE-2023-28697
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2023-1257
Disclosure Date: March 07, 2023 (last updated October 08, 2023)
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
0
Attacker Value
Unknown
CVE-2022-41313
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact"
0
Attacker Value
Unknown
CVE-2022-41312
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Description", name "switch_description"
0
Attacker Value
Unknown
CVE-2022-41311
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessage_text" name="webLocationMessage_text"
0
Attacker Value
Unknown
CVE-2022-40693
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-40691
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-40224
Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-3086
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable
to shell escape, which enables local attackers with non-superuser
credentials to gain full, unrestrictive shell access which may allow an
attacker to execute arbitrary code.
0