Show filters
296 Total Results
Displaying 81-90 of 296
Sort by:
Attacker Value
Unknown
CVE-2021-39279
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.7, OnCell G3470A-LTE-EU-T 1.7, TAP-323-EU-CT-T 1.3, TAP-323-US-CT-T 1.3, TAP-323-JP-CT-T 1.3, WDR-3124A-EU 2.3, WDR-3124A-EU-T 2.3, WDR-3124A-US 2.3, and WDR-3124A-US-T 2.3.
0
Attacker Value
Unknown
CVE-2021-33823
Disclosure Date: June 18, 2021 (last updated November 28, 2024)
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
0
Attacker Value
Unknown
CVE-2021-33824
Disclosure Date: June 18, 2021 (last updated February 22, 2025)
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.
0
Attacker Value
Unknown
CVE-2020-27185
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.
0
Attacker Value
Unknown
CVE-2020-27184
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-the-Middle attacks.
0
Attacker Value
Unknown
CVE-2020-27150
Disclosure Date: May 14, 2021 (last updated November 08, 2023)
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.
0
Attacker Value
Unknown
CVE-2020-27149
Disclosure Date: May 14, 2021 (last updated November 08, 2023)
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration changed.
0
Attacker Value
Unknown
CVE-2021-25848
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to using fixed loop counter variable without checking the actual available length via a crafted lldp packet.
0
Attacker Value
Unknown
CVE-2021-25846
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.
0
Attacker Value
Unknown
CVE-2021-25845
Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.
0