|
250231
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attack…
|
CWE-352
Origin Validation Error
|
CVE-2018-10696
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250232
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10693
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250233
|
6.1 |
MEDIUM
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The session cookie "Password508" does not have an HttpOnly flag. This allows an attacker who is able to execute a cross-site scripting attack to…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10692
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250234
|
8.8 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. Howe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10695
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250235
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wir…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10694
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250236
|
7.5 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to downloa…
|
CWE-284
Improper Access Control
|
CVE-2018-10691
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250237
|
8.1 |
HIGH
Network
|
moxa
|
awk-3121_firmware
|
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allow…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-10690
|
2024-11-21 12:41 |
2019-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250238
|
6.1 |
MEDIUM
Network
|
lantronix
|
securelinx_spider_firmware
|
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10383
|
2024-11-21 12:41 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250239
|
9.8 |
CRITICAL
Network
|
oisf
|
suricata
|
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-comm…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10244
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250240
|
9.8 |
CRITICAL
Network
|
oisf
|
libhtp
|
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10243
|
2024-11-21 12:41 |
2019-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|