Show filters
296 Total Results
Displaying 91-100 of 296
Sort by:
Attacker Value
Unknown

CVE-2021-25847

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information disclosure to attackers due to controllable loop counter variable via a crafted lldp packet.
Attacker Value
Unknown

CVE-2021-25849

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.
Attacker Value
Unknown

CVE-2020-28144

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Attacker Value
Unknown

CVE-2020-13537

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality and among them the mosquitto executable is also run.
Attacker Value
Unknown

CVE-2020-13536

Disclosure Date: November 05, 2020 (last updated February 22, 2025)
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.
Attacker Value
Unknown

CVE-2020-23639

Disclosure Date: November 02, 2020 (last updated February 22, 2025)
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
Attacker Value
Unknown

CVE-2020-25198

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a session and hijack it by stealing the user’s cookies.
Attacker Value
Unknown

CVE-2020-25192

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.
Attacker Value
Unknown

CVE-2020-25196

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
Attacker Value
Unknown

CVE-2020-25153

Disclosure Date: October 13, 2020 (last updated February 22, 2025)
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.