Vulnerabilidades em Moxa

128 resultados
Análise Vexday

Com 119 CVEs catalogadas, o portfólio da Moxa apresenta taxa de exploração ativa abaixo da média geral do catálogo CISA KEV, sem registros confirmados de exploração em produção até o momento. No entanto, a ausência de PoCs públicas conhecidas não elimina o risco: o tipo de falha mais recorrente é CWE-78 (OS Command Injection), categoria historicamente atrativa para atacantes em ambientes de tecnologia operacional e redes industriais. A CVE mais perigosa em evidência hoje é CVE-2022-40224, com EPSS de 0,6469 — valor que indica probabilidade relevante de exploração próxima e merece atenção prioritária nas esteiras de patch. As 17 vulnerabilidades de severidade crítica e as 8 CVEs surgidas nos últimos 90 dias reforçam a necessidade de monitoramento contínuo para equipes que operam equipamentos Moxa em ambientes críticos.

CVE-2020-25153CRITICALMOXA NPort IAW5000A-I/O SeriesEPSS 1.6%CVE-2018-18395Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.EPSS 1.5%CVE-2022-40691MEDIUMAn information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. EPSS 1.5%CVE-2023-33235HIGHMXsecurity Command Injection VulnerabilityEPSS 1.5%CVE-2024-9139HIGHOS Command Injection in Restricted CommandEPSS 1.4%CVE-2016-8726HIGHAn exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa AEPSS 1.4%CVE-2016-8723HIGHAn exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmwareEPSS 1.4%CVE-2020-25198HIGHMOXA NPort IAW5000A-I/O SeriesEPSS 1.4%CVE-2016-8720LOWAn exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point rEPSS 1.4%CVE-2016-8712MEDIUMAn exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. TheEPSS 1.4%CVE-2020-25194HIGHMOXA NPort IAW5000A-I/O SeriesEPSS 1.3%CVE-2016-8722MEDIUMAn exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802EPSS 1.3%CVE-2016-8725MEDIUMAn exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access point EPSS 1.3%CVE-2020-25192MEDIUMMOXA NPort IAW5000A-I/O SeriesEPSS 1.2%CVE-2021-38456CRITICALMoxa MXview Network Management SoftwareEPSS 1.2%CVE-2024-9138HIGHPrivilege Escalation in Cellular Router, Secure Router, and Network Security AppliancesEPSS 1.1%CVE-2023-33239HIGHSecond Order Command-injection Vulnerability in the Key-generation FunctionEPSS 1.1%CVE-2018-18390User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.EPSS 1.1%CVE-2022-41312MEDIUMA stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2EPSS 1.1%CVE-2022-41313MEDIUMA stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2EPSS 1.1%