Skip to main content

Vendor/product archive

moxa / awk-3121_firmware CVEs

Beta · best-effort

14 CVEs tagged to moxa / awk-3121_firmware1 Critical, 11 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2018-10703

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the sa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10702

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the sa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10701

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troubleshoot any issues. However, the sa…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10700

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10699

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for con…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10698

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM posit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10697

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is wor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10696

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10695

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the de…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10694

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10693

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10692

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10691

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10690

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the we…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1