|
255131
|
7.2 |
HIGH
Network
|
synology
|
diskstation_manager
|
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter.
|
CWE-77
Command Injection
|
CVE-2017-12075
|
2024-11-21 12:08 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255132
|
7.5 |
HIGH
Network
|
rockwellautomation
|
micrologix_1400_b_firmware
|
An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resu…
|
CWE-200
Information Exposure
|
CVE-2017-12092
|
2024-11-21 12:08 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255133
|
8.0 |
HIGH
Adjacent
|
moxa
|
edr-810_firmware
|
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and cou…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-12129
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255134
|
7.5 |
HIGH
Network
|
moxa
|
edr-810_firmware
|
An exploitable information disclosure vulnerability exists in the Server Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted TCP packet can cause information disclosure. An a…
|
CWE-200
Information Exposure
|
CVE-2017-12128
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255135
|
4.4 |
MEDIUM
Local
|
moxa
|
edr-810_firmware
|
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-12127
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255136
|
8.8 |
HIGH
Network
|
moxa
|
edr-810_firmware
|
An exploitable cross-site request forgery vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP packet can cause cross-site request forger…
|
CWE-352
Origin Validation Error
|
CVE-2017-12126
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255137
|
8.8 |
HIGH
Network
|
moxa
|
edr-810_firmware
|
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in …
|
CWE-78
OS Command
|
CVE-2017-12125
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255138
|
6.5 |
MEDIUM
Network
|
moxa
|
edr-810_firmware
|
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting …
|
CWE-20 CWE-476
Improper Input Validation NULL Pointer Dereference
|
CVE-2017-12124
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255139
|
8.8 |
HIGH
Adjacent
|
moxa
|
edr-810_firmware
|
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-12123
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255140
|
8.8 |
HIGH
Network
|
moxa
|
edr-810_firmware
|
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in …
|
CWE-78
OS Command
|
CVE-2017-12121
|
2024-11-21 12:08 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|