Skip to main content

Vendor archive

moxa CVEs

Beta · best-effort

289 CVEs tagged to vendor moxa63 Critical, 161 High, 60 Medium, 5 Low, 0 Unrated.

CVE-2024-4740

Published Oct 18, 2024

MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerability could allow an attacker to tamper with sensitive data.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4739

Published Oct 18, 2024

The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacke…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6787

Published Sep 21, 2024

This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it is used (TOCTOU). By exploiting this race condition, an att…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6786

Published Sep 21, 2024

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling them to read arbitrary files on the system. This could lead to…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4641

Published Jun 25, 2024

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker…

CVSS 6.3 · Medium

CVE-2024-4640

Published Jun 25, 2024

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past th…

CVSS 7.1 · High

CVE-2024-4639

Published Jun 25, 2024

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify…

CVSS 7.1 · High

CVE-2024-4638

Published Jun 25, 2024

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker coul…

CVSS 7.1 · High

CVE-2024-0387

Published Feb 26, 2024

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have i…

CVSS 6.5 · Medium

CVE-2023-39983

Published Sep 2, 2023

A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnera…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39982

Published Sep 2, 2023

A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may put the confidentiality and integrity of SSH communications at risk on the affect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39981

Published Sep 2, 2023

A vulnerability that allows for unauthorized access has been discovered in MXsecurity versions prior to v1.0.1. This vulnerability arises from inadequate authentication measures,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 289 CVEsPage 1 of 12