Moxa EDR 810 Series vulnerabilities

Overview :
Moxa EDR 810 Series Improper Input Validation and Improper Access Control vulnerabilities
Affected Product(s) :
  • EDR-810: All versions 5.1 and prior
Vulnerability Details :
CVE ID : CVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.

CVE-2019-10963 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).

CVE ID : CVE-2019-10969
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.

CVE-2019-10969 has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been calculated; the CVSS vector string is (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Solution :
Moxa recommends users upgrade to the latest firmware, v5.2 or later.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2022-42457 : GENEREX CS141 PRIOR 2.08 WEB INTERFACE GXSERVE-UPDATE.SH RUN_UPDATE PRIVILEGE ESCALATION

CVE-2022-42457 : GENEREX CS141 PRIOR 2.08 WEB INTERFACE GXSERVE-UPDATE.SH RUN_UPDATE PRIVILEGE ESCALATION

Description Generex CS141 before 2.08 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh

CVE-2022-36961 : SOLARWINDS ORION PLATFORM VERB SQL INJECTION

CVE-2022-36961 : SOLARWINDS ORION PLATFORM VERB SQL INJECTION

Description A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege

CVE-2022-42302 : VERITAS NETBACKUP UP TO 10.0 NBFSMCLIENT SERVICE SQL INJECTION

CVE-2022-42302 : VERITAS NETBACKUP UP TO 10.0 NBFSMCLIENT SERVICE SQL INJECTION

Description An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable