Vulnerabilities > Moxa > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-03-05 CVE-2019-6565 Cross-site Scripting vulnerability in Moxa products
Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which may be used to send a malicious script.
network
low complexity
moxa CWE-79
6.1
2019-03-05 CVE-2019-6559 Resource Exhaustion vulnerability in Moxa products
Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may cause the switch to crash.
network
low complexity
moxa CWE-400
6.5
2019-03-05 CVE-2019-6524 Improper Restriction of Excessive Authentication Attempts vulnerability in Moxa products
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
network
low complexity
moxa CWE-307
5.0
2019-03-05 CVE-2019-6520 Unspecified vulnerability in Moxa products
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.
network
low complexity
moxa
5.0
2019-03-05 CVE-2019-6518 Missing Encryption of Sensitive Data vulnerability in Moxa products
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
network
low complexity
moxa CWE-311
5.0
2018-10-19 CVE-2018-18394 Cleartext Storage of Sensitive Information vulnerability in Moxa Thingspro 2.1
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa CWE-312
5.0
2018-10-19 CVE-2018-18393 Unspecified vulnerability in Moxa Thingspro 2.1
Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa
5.0
2018-10-19 CVE-2018-18392 Unspecified vulnerability in Moxa Thingspro 2.1
Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa
6.5
2018-10-19 CVE-2018-18391 Unspecified vulnerability in Moxa Thingspro 2.1
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa
6.5
2018-10-19 CVE-2018-18390 Information Exposure vulnerability in Moxa Thingspro 2.1
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
network
low complexity
moxa CWE-200
5.0