Skip to main content

Vendor archive

moxa CVEs

Beta · best-effort

289 CVEs tagged to vendor moxa63 Critical, 161 High, 60 Medium, 5 Low, 0 Unrated.

CVE-2018-18395

Published Oct 19, 2018

Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18394

Published Oct 19, 2018

Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18393

Published Oct 19, 2018

Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-18392

Published Oct 19, 2018

Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18391

Published Oct 19, 2018

User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18390

Published Oct 19, 2018

User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16282

Published Sep 20, 2018

A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14439

Published May 14, 2018

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14438

Published May 14, 2018

Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of servi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14437

Published May 14, 2018

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14436

Published May 14, 2018

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14435

Published May 14, 2018

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer de…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-14434

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14433

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14432

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12129

Published May 14, 2018

An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypt…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12128

Published May 14, 2018

An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause informat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12127

Published May 14, 2018

A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear t…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12126

Published May 14, 2018

An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12125

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12124

Published May 14, 2018

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer de…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12123

Published May 14, 2018

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at net…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12121

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-12120

Published May 14, 2018

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege esca…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 176-200 of 289 CVEsPage 8 of 12