VYPR

Oncell Central Manager

by Moxa

CVEs (2)

  • CVE-2015-6481HigDec 21, 2015
    risk 0.54cvss 8.3epss 0.02

    The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.

  • CVE-2015-6480HigDec 21, 2015
    risk 0.54cvss 8.3epss 0.02

    The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.