VYPR
Vendor

Moog

Products
4
CVEs
4
Across products
5
Status
Private

Products

4

Recent CVEs

4
  • CVE-2020-24054Aug 21, 2020
    risk 0.00cvss epss 0.01

    The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary…

  • CVE-2020-24053Aug 21, 2020
    risk 0.00cvss epss 0.00

    Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols.

  • CVE-2020-24052Aug 21, 2020
    risk 0.00cvss epss 0.01

    Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

  • CVE-2020-24051Aug 21, 2020
    risk 0.00cvss epss 0.00

    The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker…