Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tn 5916 Wv T Firmware HIGH 7.5
CVE-2021-46082

Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to co…

Fix: after 3.1
Fix from $1,950 2022-02-18
Tn 5900 Firmware CRITICAL 9.8
CVE-2021-46560

The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.

Fix: after 3.1
Fix from $2,300 2022-01-26
Tn 5900 Firmware HIGH 7.5
CVE-2021-46559

The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protect…

Fix: after 3.1
Fix from $1,950 2022-01-26
Mgate Mb3180 Firmware HIGH 7.5
CVE-2021-4161

The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This coul…

Fix: after 4.1
Fix from $1,950 2021-12-27
Mxview CRITICAL 10.0
CVE-2021-38454EPSS 16%

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Mxview CRITICAL 9.8
CVE-2021-38456

A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access …

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Mxview CRITICAL 9.8
CVE-2021-38458

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Mxview CRITICAL 9.1
CVE-2021-38452

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $2,300 2021-10-12
Mxview HIGH 7.5
CVE-2021-38460

A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite crit…

Fix: after 3.2.2
Fix from $1,950 2021-10-12
Wac 2004 Firmware HIGH 8.8
CVE-2021-39279

Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell…

No fix yet
Fix from $1,950 2021-09-07
Wac 2004 Firmware MEDIUM 6.1
CVE-2021-39278

Certain MOXA devices allow reflected XSS via the Config Import menu. This affects WAC-2004 1.7, WAC-1001 2.1, WAC-1001-T 2.1, OnCell G3470A-LTE-EU 1.…

No fix yet
Fix from $1,600 2021-09-07
Mgate Mb3180 Firmware HIGH 7.5
CVE-2021-33823

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's re…

No fix yet
Fix from $1,950 2021-06-18
Mgate Mb3180 Firmware HIGH 7.5
CVE-2021-33824

An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which c…

No fix yet
Fix from $1,950 2021-06-18
Nport Ia5150a Firmware HIGH 7.5
CVE-2020-27185

Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability co…

Fix: after 1.7
Fix from $1,950 2021-05-14
Nport Ia5150a Firmware MEDIUM 5.9
CVE-2020-27184

The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server…

Fix: after 1.7
Fix from $1,600 2021-05-14
Nport Ia5150a Firmware HIGH 7.5
CVE-2020-27150

In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and …

Fix: after 1.7
Fix from $1,950 2021-05-14
Nport Ia5150a Firmware MEDIUM 6.5
CVE-2020-27149

By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the w…

Fix: 1.5 / 2.0+
Fix from $1,600 2021-05-14
Vport 06ec 2v26m Firmware CRITICAL 9.1
CVE-2021-25847

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information …

Fix: after 1.1
Fix from $2,300 2021-05-10
Vport 06ec 2v26m Firmware CRITICAL 9.1
CVE-2021-25848

Improper validation of the length field of LLDP-MED TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows information …

Fix: after 1.1
Fix from $2,300 2021-05-10
Vport 06ec 2v26m Firmware HIGH 7.5
CVE-2021-25845

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial…

Mitigation only
Fix from $1,950 2021-05-10
Vport 06ec 2v26m Firmware HIGH 7.5
CVE-2021-25846

Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial…

Fix: after 1.1
Fix from $1,950 2021-05-10
Vport 06ec 2v26m Firmware HIGH 7.5
CVE-2021-25849

An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV l…

Fix: after 1.1
Fix from $1,950 2021-05-10
Edr G903 Firmware CRITICAL 9.8
CVE-2020-28144

Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Fir…

Fix: after 5.6
Fix from $2,300 2021-02-03
Nport Iaw5000a I\/o Firmware CRITICAL 9.8
CVE-2020-25190

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cle…

Fix: after 2.1
Fix from $2,300 2020-12-23
Nport Iaw5000a I\/o Firmware CRITICAL 9.8
CVE-2020-25196

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force …

Fix: after 2.1
Fix from $2,300 2020-12-23
Nport Iaw5000a I\/o Firmware HIGH 8.8
CVE-2020-25194

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with…

Fix: after 2.1
Fix from $1,950 2020-12-23
Nport Iaw5000a I\/o Firmware HIGH 8.8
CVE-2020-25198

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, whic…

Fix: after 2.1
Fix from $1,950 2020-12-23
Nport Iaw5000a I\/o Firmware HIGH 7.5
CVE-2020-25153

The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.

Fix: after 2.1
Fix from $1,950 2020-12-23
Nport Iaw5000a I\/o Firmware MEDIUM 5.3
CVE-2020-25192

The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authori…

Fix: after 2.1
Fix from $1,600 2020-12-23
Mxview HIGH 7.8
CVE-2020-13536

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on t…

No fix yet
Fix from $1,950 2020-11-05