VYPR

Vendor CVEs

Moxa

All CVEs

320 total · sorted by risk
  • CVE-2023-1257HigMar 7, 2023
    risk 0.49cvss 7.6epss 0.00

    An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the…

  • CVE-2022-40693HigFeb 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger…

  • CVE-2022-2043HigAug 31, 2022
    risk 0.49cvss 7.5epss 0.01

    MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unresponsive.

  • CVE-2021-40392HigApr 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

  • CVE-2021-32970HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.02

    Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.

  • CVE-2021-32968HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.02

    Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

  • CVE-2021-46082HigFeb 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.

  • CVE-2021-46559HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

  • CVE-2021-38460HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38452HigOct 12, 2021
    risk 0.49cvss 7.5epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-33824HigJun 18, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is…

  • CVE-2021-33823HigJun 18, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.

  • CVE-2020-27185HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, device configuration, and other sensitive data transmitted over Moxa Service.

  • CVE-2020-27150HigMay 14, 2021
    risk 0.49cvss 7.5epss 0.01

    In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-shared key” doesn’t set.

  • CVE-2021-25849HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An integer underflow was discovered in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, improper validation of the PortID TLV leads to Denial of Service via a crafted lldp packet.

  • CVE-2021-25846HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a negative number passed to the memcpy function via a crafted lldp packet.

  • CVE-2021-25845HigMay 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper validation of the ChassisID TLV in userdisk/vport_lldpd in Moxa Camera VPort 06EC-2V Series, version 1.1, allows attackers to cause a denial of service due to a NULL pointer dereference via a crafted lldp packet.

  • CVE-2020-25190HigDec 23, 2020
    risk 0.49cvss 7.5epss 0.01

    The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.

  • CVE-2020-7001HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

  • CVE-2020-6997HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, sensitive information is transmitted over some web applications in cleartext.

  • CVE-2020-6979HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the affected products use a hard-coded cryptographic key, increasing the possibility that confidential data can be recovered.

  • CVE-2020-6993HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.02

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, an attacker can gain access to sensitive information from the web service without authorization.

  • CVE-2020-6987HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a weak cryptographic algorithm, which may allow confidential information to be disclosed.

  • CVE-2020-6983HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the affected products use a hard-coded cryptographic key, which increases the possibility that confidential data can be recovered.

  • CVE-2020-7003HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

  • CVE-2019-18242HigMar 24, 2020
    risk 0.49cvss 7.5epss 0.02

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.

  • CVE-2019-9104HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.

  • CVE-2019-9101HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the…

  • CVE-2019-9098HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.

  • CVE-2019-18238HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.01

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.

  • CVE-2019-5148HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker…

  • CVE-2019-5137HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.02

    The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

  • CVE-2019-19707HigDec 11, 2019
    risk 0.49cvss 7.5epss 0.01

    On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.

  • CVE-2018-11424HigJul 3, 2019
    risk 0.49cvss 7.5epss 0.01

    There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11425.

  • CVE-2018-11423HigJul 3, 2019
    risk 0.49cvss 7.5epss 0.01

    There is Memory corruption in the web interface Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior, different vulnerability than CVE-2018-11420.

  • CVE-2018-10691HigJun 7, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.

  • CVE-2019-6520HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.02

    Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

  • CVE-2019-6518HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.01

    Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

  • CVE-2018-18390HigOct 19, 2018
    risk 0.49cvss 7.5epss 0.01

    User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.

  • CVE-2018-10632HigJul 24, 2018
    risk 0.49cvss 7.5epss 0.02

    In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.

  • CVE-2017-14439HigMay 14, 2018
    risk 0.49cvss 7.5epss 0.02

    Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4001/tcp to trigger this vulnerability.

  • CVE-2017-14438HigMay 14, 2018
    risk 0.49cvss 7.5epss 0.02

    Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.

  • CVE-2017-14437HigMay 14, 2018
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_LOG.ini"…

  • CVE-2017-14436HigMay 14, 2018
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG2.ini"…

  • CVE-2017-14435HigMay 14, 2018
    risk 0.49cvss 7.5epss 0.02

    An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG.ini"…

  • CVE-2018-7506HigApr 6, 2018
    risk 0.49cvss 7.5epss 0.02

    The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

  • CVE-2018-5453HigMar 5, 2018
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.

  • CVE-2017-13699HigNov 23, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reverse the password…

  • CVE-2017-13698HigNov 23, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them against a production switch that has the default keys embedded.

  • CVE-2017-13703HigNov 17, 2017
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.

Page 4 of 7