Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-6787
Disclosure Date: September 21, 2024 (last updated October 01, 2024)
This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an attacker can write arbitrary files to the system. This could allow the attacker to execute malicious code and potentially cause file losses.
0
Attacker Value
Unknown
CVE-2024-6786
Disclosure Date: September 21, 2024 (last updated October 01, 2024)
The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to the disclosure of sensitive information, such as configuration files and JWT signing secrets.
0
Attacker Value
Unknown
CVE-2024-6785
Disclosure Date: September 21, 2024 (last updated September 28, 2024)
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
0
Attacker Value
Unknown
CVE-2021-40390
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-40392
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2021-38454
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
0
Attacker Value
Unknown
CVE-2021-38458
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
0
Attacker Value
Unknown
CVE-2021-38456
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
0
Attacker Value
Unknown
CVE-2021-38460
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
0
Attacker Value
Unknown
CVE-2021-38452
Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
0