Moxa
Moxa Mxview: vulnerabilidades y CVE
Moxa Mxview tiene 13 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-40392 | Alta (7.5) | 0.60% | — | 14 abr 2022 | An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic… |
| CVE-2021-40390 | Crítica (9.8) | 2.5% | — | 14 abr 2022 | An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to… |
| CVE-2021-38460 | Alta (7.5) | 1.8% | — | 12 oct 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
| CVE-2021-38458 | Crítica (9.8) | 1.8% | — | 12 oct 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
| CVE-2021-38456 | Crítica (9.8) | 1.2% | — | 12 oct 2021 | A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords |
| CVE-2021-38454 | Crítica (10) | 16% | — | 12 oct 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
| CVE-2021-38452 | Crítica (9.1) | 1.7% | — | 12 oct 2021 | A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries. |
| CVE-2020-13537 | Alta (7.8) | 0.54% | — | 5 nov 2020 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or… |
| CVE-2020-13536 | Alta (7.8) | 0.55% | — | 5 nov 2020 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or… |
| CVE-2018-7506 | Alta (7.5) | 1.9% | — | 6 abr 2018 | The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information. |
| CVE-2017-14030 | Alta (7.8) | 0.37% | — | 12 ene 2018 | An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the… |
| CVE-2017-7456 | Alta (7.5) | 29% | — | 14 abr 2017 | Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials. |
| CVE-2017-7455 | Alta (7.5) | 16% | — | 14 abr 2017 | Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control. |