Vulnerabilidades em Moxa

128 resultados
Análise Vexday

Com 119 CVEs catalogadas, o portfólio da Moxa apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem registros confirmados de exploração em produção até o momento. No entanto, a ausência de PoCs públicas conhecidas não elimina o risco: o tipo de falha mais recorrente é CWE-78 (OS Command Injection), categoria historicamente atrativa para atacantes em ambientes de tecnologia operacional e redes industriais. A CVE mais perigosa em evidência hoje é CVE-2022-40224, com EPSS de 0,6469 — valor que indica probabilidade relevante de exploração próxima e merece atenção prioritária nas esteiras de patch. As 17 vulnerabilidades de severidade crítica e as 8 CVEs surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo para equipes que operam equipamentos Moxa em ambientes críticos.

CVE-2022-40224MEDIUMA denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A speciallyEPSS 64.7%CVE-2021-38454CRITICALMoxa MXview Network Management SoftwareEPSS 15.8%CVE-2020-8858HIGHThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.EPSS 8.6%CVE-2016-8724MEDIUMAn exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point runningEPSS 4.2%CVE-2016-8721CRITICALAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access PointEPSS 3.3%CVE-2015-6458Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMEPSS 2.8%CVE-2015-6457Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMEPSS 2.8%CVE-2021-32976CRITICALMoxa NPort IAW5000A-I/O Series Serial Device Server Stack-based Buffer OverflowEPSS 2.7%CVE-2021-32974CRITICALMoxa NPort IAW5000A-I/O Series Serial Device Server Improper Input ValidationEPSS 2.7%CVE-2021-40390CRITICALAn authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP reqEPSS 2.4%CVE-2018-18396Remote Code Execution in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.EPSS 2.3%CVE-2018-10632In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not resEPSS 2.2%CVE-2021-38458CRITICALMoxa MXview Network Management SoftwareEPSS 1.8%CVE-2021-38460HIGHMoxa MXview Network Management SoftwareEPSS 1.8%CVE-2020-25196CRITICALMOXA NPort IAW5000A-I/O SeriesEPSS 1.8%CVE-2024-9140CRITICALMoxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulneEPSS 1.8%CVE-2021-32968HIGHMoxa NPort IAW5000A-I/O Series Serial Device Server Classic Buffer OverflowEPSS 1.7%CVE-2016-8727An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. RetEPSS 1.7%CVE-2021-32970HIGHMoxa NPort IAW5000A-I/O Series Serial Device Server Improper Input ValidationEPSS 1.7%CVE-2021-38452HIGHMoxa MXview Network Management SoftwareEPSS 1.7%