Vulnerability index

Browse CVEs

280 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Awk 3121 Firmware HIGH 8.8
CVE-2018-10703

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides functionality so that an administrator can run scripts on the device to troublesho…

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware HIGH 8.1
CVE-2018-10690

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism f…

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware HIGH 8.1
CVE-2018-10694

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism …

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware HIGH 7.5
CVE-2018-10691

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, th…

No fix yet
Fix from $1,950 2019-06-07
Awk 3121 Firmware MEDIUM 6.1
CVE-2018-10692

An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who i…

No fix yet
Fix from $1,600 2019-06-07
Awk 3121 Firmware MEDIUM 6.1
CVE-2018-10700EPSS 38%

An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However,…

No fix yet
Fix from $1,600 2019-06-07
Iks G6824a Firmware CRITICAL 9.8
CVE-2019-6526

Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Vers…

Fix: after 4.5
Fix from $2,300 2019-04-15
Softcms HIGH 8.8
CVE-2015-6457

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version…

Fix: after 1.3
Fix from $1,950 2019-03-21
Softcms HIGH 8.8
CVE-2015-6458

Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version…

Fix: after 1.3
Fix from $1,950 2019-03-21
Oncell G3100v2 Firmware MEDIUM 6.1
CVE-2016-5819

Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross…

Fix: 1.7 / 2.8+
Fix from $1,600 2019-03-21
Iks G6824a Firmware CRITICAL 9.8
CVE-2019-6524

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover pas…

Fix: after 4.5
Fix from $2,300 2019-03-05
Iks G6824a Firmware CRITICAL 9.8
CVE-2019-6557EPSS 5%

Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.

Fix: after 4.5
Fix from $2,300 2019-03-05
Iks G6824a Firmware CRITICAL 9.8
CVE-2019-6563

Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could…

Fix: after 4.5
Fix from $2,300 2019-03-05
Iks G6824a Firmware CRITICAL 9.1
CVE-2019-6522

Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an atta…

Fix: after 4.5
Fix from $2,300 2019-03-05
Iks G6824a Firmware HIGH 8.8
CVE-2019-6561

Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.

Fix: after 4.5
Fix from $1,950 2019-03-05
Iks G6824a Firmware HIGH 7.5
CVE-2019-6518

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

Fix: after 4.5
Fix from $1,950 2019-03-05
Iks G6824a Firmware HIGH 7.5
CVE-2019-6520

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration ch…

Fix: after 4.5
Fix from $1,950 2019-03-05
Iks G6824a Firmware MEDIUM 6.5
CVE-2019-6559

Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash.

Fix: after 4.5
Fix from $1,600 2019-03-05
Iks G6824a Firmware MEDIUM 6.1
CVE-2019-6565

Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which …

Fix: after 4.5
Fix from $1,600 2019-03-05
Nport W2x50a Firmware HIGH 8.8
CVE-2018-19659

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…

Fix: 2.2+
Fix from $1,950 2018-12-06
Nport W2x50a Firmware HIGH 8.8
CVE-2018-19660EPSS 29%

An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A products with firmware befor…

Fix: 2.2+
Fix from $1,950 2018-12-06
Thingspro CRITICAL 9.8
CVE-2018-18393

Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $2,300 2018-10-19
Thingspro CRITICAL 9.8
CVE-2018-18394

Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $2,300 2018-10-19
Thingspro CRITICAL 9.8
CVE-2018-18395

Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

No fix yet
Fix from $2,300 2018-10-19
Thingspro CRITICAL 9.8
CVE-2018-18396

Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

No fix yet
Fix from $2,300 2018-10-19
Thingspro HIGH 8.8
CVE-2018-18391

User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $1,950 2018-10-19
Thingspro HIGH 8.8
CVE-2018-18392

Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $1,950 2018-10-19
Thingspro HIGH 7.5
CVE-2018-18390

User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

Mitigation only
Fix from $1,950 2018-10-19
Edr 810 Firmware HIGH 8.8
CVE-2018-16282EPSS 5%

A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS…

No fix yet
Fix from $1,950 2018-09-20
Nport 5230 Firmware HIGH 7.5
CVE-2018-10632

In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, …

Mitigation only
Fix from $1,950 2018-07-24