Talos Moxa vulnerabilities
19 known vulnerabilities affecting talos/moxa.
Total CVEs
19
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2017-12129HIGHCVSS 8.0vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12129 [HIGH] CWE-327 CVE-2017-12129: An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.
cvelistv5nvd
CVE-2017-14434HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14434 [HIGH] CWE-78 CVE-2017-14434: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetmask0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.
cvelistv5nvd
CVE-2017-12125HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12125 [HIGH] CWE-78 CVE-2017-12125: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.
cvelistv5nvd
CVE-2017-12128HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12128 [HIGH] CWE-200 CVE-2017-12128: An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An attacker can send a crafted TCP packet to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14439HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14439 [HIGH] CWE-20 CVE-2017-14439: Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4001/tcp to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14433HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14433 [HIGH] CWE-78 CVE-2017-14433: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the remoteNetwork0= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.
cvelistv5nvd
CVE-2017-12120HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12120 [HIGH] CVE-2017-12120: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the "/goform/net_WebPingGetValue" URI to trigger this vulnerability.
cvelistv5
CVE-2017-14435HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14435 [HIGH] CWE-476 CVE-2017-14435: An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG.ini" without a cookie header to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14436HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14436 [HIGH] CWE-476 CVE-2017-14436: An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG2.ini" without a cookie header to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14437HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14437 [HIGH] CWE-476 CVE-2017-14437: An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_LOG.ini" without a cookie header to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14432HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14432 [HIGH] CWE-78 CVE-2017-14432: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the openvpnServer0_tmp= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerabilit
cvelistv5nvd
CVE-2017-12123HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12123 [HIGH] CWE-522 CVE-2017-12123: An exploitable clear text transmission of password vulnerability exists in the web server and telnet
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.
cvelistv5nvd
CVE-2017-12121HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12121 [HIGH] CWE-78 CVE-2017-12121: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the rsakey\_name= parm in the "/goform/WebRSAKEYGen" uri to trigger this vulnerability.
cvelistv5nvd
CVE-2017-12126HIGHCVSS 8.8vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12126 [HIGH] CWE-352 CVE-2017-12126: An exploitable cross-site request forgery vulnerability exists in the web server functionality of Mo
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forgery. An attacker can create malicious HTML to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14438HIGHCVSS 7.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-14438 [HIGH] CWE-20 CVE-2017-14438: Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.
cvelistv5nvd
CVE-2017-12127MEDIUMCVSS 4.4vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12127 [MEDIUM] CWE-522 CVE-2017-12127: A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 b
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
cvelistv5nvd
CVE-2017-12124MEDIUMCVSS 6.5vMoxa EDR-810 V4.1 build 170303172018-05-14
CVE-2017-12124 [MEDIUM] CWE-20 CVE-2017-12124: An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-81
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in the web server crashing. An attacker can send a crafted URI to trigger this vulnerability.
cvelistv5nvd
CVE-2017-14459CRITICALCVSS 9.8PoCvMoxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client versions 1.4 - 1.9. In addition, versions prior to 1.4 appear similarly vulnerable to injection, but not as easily exploitable (described below). Other models in the AWK product line may likewise be vulnerable but have not been tested.2018-04-11
CVE-2017-14459 [CRITICAL] CWE-78 CVE-2017-14459: An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login funct
An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote,
cvelistv5nvd
CVE-2016-8717CRITICALCVSS 9.8vMoxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client 1.12018-04-02
CVE-2016-8717 [CRITICAL] CWE-798 CVE-2016-8717: An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Acc
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.
cvelistv5nvd