Skip to main content

Vendor archive

moxa CVEs

Beta · best-effort

289 CVEs tagged to vendor moxa63 Critical, 161 High, 60 Medium, 5 Low, 0 Unrated.

CVE-2018-10698

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM posit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-10697

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is wor…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10696

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10695

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the de…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10694

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10693

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10692

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10691

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10690

Published Jun 7, 2019

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the we…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6458

Published Mar 21, 2019

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to addre…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-6457

Published Mar 21, 2019

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to addre…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5819

Published Mar 21, 2019

Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which m…

CVSS 6.1 · Medium

CVE-2018-18396

Published Oct 19, 2018

Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 151-175 of 289 CVEsPage 7 of 12