|
246831
|
6.1 |
MEDIUM
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.19 devices. It provides functionality so that an administrator can change the name of the device. However, the same functionality allows an attacker to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10700
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246832
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides certfile upload functionality so that an administrator can upload a certificate file used for connecting to the wirel…
|
CWE-78
OS Command
|
CVE-2018-10699
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246833
|
9.8 |
CRITICAL
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff …
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10698
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246834
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The Moxa AWK 3121 provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. Howe…
|
CWE-78
OS Command
|
CVE-2018-10697
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246835
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attack…
|
CWE-352
Origin Validation Error
|
CVE-2018-10696
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246836
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10693
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246837
|
6.1 |
MEDIUM
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10692
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246838
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. Howe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10695
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246839
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wir…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10694
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246840
|
7.5 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to downloa…
|
CWE-284
Improper Access Control
|
CVE-2018-10691
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|