Vulnerabilities > Motorola

DATE CVE VULNERABILITY TITLE RISK
2022-07-26 CVE-2022-30271 Use of Hard-coded Credentials vulnerability in Motorola Ace1000 Firmware
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists.
network
low complexity
motorola CWE-798
critical
9.8
2022-07-26 CVE-2022-30272 Insufficient Verification of Data Authenticity vulnerability in Motorola Ace1000 Firmware
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity.
network
low complexity
motorola CWE-345
7.2
2022-07-26 CVE-2022-30274 Use of Hard-coded Credentials vulnerability in Motorola Ace1000 Firmware
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely.
network
low complexity
motorola CWE-798
critical
9.8
2022-07-26 CVE-2022-30276 Missing Authentication for Critical Function vulnerability in Motorola products
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement.
network
low complexity
motorola CWE-306
7.5
2022-04-22 CVE-2021-3898 Improper Certificate Validation vulnerability in Motorola Device Help and Ready for
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.
network
low complexity
motorola CWE-295
6.5
2021-12-15 CVE-2021-38701 Cross-site Scripting vulnerability in Motorola products
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI.
network
low complexity
motorola CWE-79
4.8
2021-08-17 CVE-2021-3458 Improper Authentication vulnerability in Motorola Mm1000 Firmware
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
low complexity
motorola CWE-287
4.6
2021-08-17 CVE-2021-3459 OS Command Injection vulnerability in Motorola Mm1000 Firmware
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.
low complexity
motorola CWE-78
6.8
2021-07-21 CVE-2020-21932 Improper Authentication vulnerability in Motorola CX2 Firmware 1.0.2
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
network
low complexity
motorola CWE-287
5.3
2021-07-21 CVE-2020-21933 Information Exposure Through Log Files vulnerability in Motorola CX2 Firmware 1.0.2
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
network
low complexity
motorola CWE-532
7.5