VYPR

Mxview

by Moxa

CVEs (9)

  • CVE-2017-7456HigApr 14, 2017
    risk 0.54cvss 7.5epss 0.29

    Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

  • CVE-2017-7455HigApr 14, 2017
    risk 0.53cvss 7.5epss 0.16

    Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

  • CVE-2017-14030HigJan 12, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.

  • CVE-2018-7506HigApr 6, 2018
    risk 0.49cvss 7.5epss 0.02

    The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

  • CVE-2021-38460Oct 12, 2021
    risk 0.00cvss epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38458Oct 12, 2021
    risk 0.00cvss epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38454Oct 12, 2021
    risk 0.00cvss epss 0.16

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38456Oct 12, 2021
    risk 0.00cvss epss 0.01

    A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

  • CVE-2021-38452Oct 12, 2021
    risk 0.00cvss epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.