VYPR

SDS-3008 Series Industrial Ethernet Switch

by Moxa

CVEs (6)

  • CVE-2022-40224HigFeb 7, 2023
    risk 0.54cvss 7.5epss 0.65

    A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-40693HigFeb 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger…

  • CVE-2022-41313MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-41312MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-41311MedFeb 7, 2023
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-40691MedFeb 7, 2023
    risk 0.35cvss 5.3epss 0.01

    An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this…