VYPR

EXO Series EXVF5C-2 and EXVP7C2-3

by Moog

CVEs (3)

  • CVE-2020-24054CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.03

    The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary…

  • CVE-2020-24052CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.02

    Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

  • CVE-2020-24053HigAug 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.