CVE-2015-6464
published 2015-09-11CVE-2015-6464: The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only…
PriorityP341high8.5CVSS 2.0
AVNACLAuSCNICAC
EPSS
2.00%
78.5th percentile
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | eds-405a_firmware | <= 3.4 | — |
| moxa | eds-408a_firmware | <= 3.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa Industrial Managed Switch Vulnerabilities
cisa_ics·2018-08-27
Moxa Industrial Managed Switch Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa Industrial Managed Switch Vulnerabilities
Last RevisedAugust 27, 2018
Alert CodeICSA-15-246-03
## OVERVIEW
Erwin Paternotte of Applied RiskApplied Risk Security Advisory AR2015001, Multiple Vulnerabilities in Moxa industrial manages switches, http://applied-risk.com/application/files/3414/4060/7148/Advisory_Moxa_Multiple_Vulnerabilities.pdf, web site last accessed September 3, 2015. has identified vulnerabilities in the Moxa EDS-405A/EDS-408A series managed Ethernet switches. Moxa has produced a firmware update to mitigate these vulnerabilities.
These vulnerabilities could
GHSA
GHSA-64gm-j8rj-qrxj: The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3
ghsa_unreviewed·2022-05-17
CVE-2015-6464 [HIGH] GHSA-64gm-j8rj-qrxj: The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3
The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-09-11
Published