CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2022-06-13
N/A
7.2 HIGH
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability.
An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability.
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2022-06-13
N/A
8.8 HIGH
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
750-830_firmware, 750-830, 750-849_firmware, 750-849, 750-871_firmware, 750-871, 750-872_firmware, 750-872, 750-873_firmware, 750-873
2020-03-13
N/A
9.1 CRITICAL
An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges.
750-830_firmware, 750-830, 750-849_firmware, 750-849, 750-871_firmware, 750-871, 750-872_firmware, 750-872, 750-873_firmware, 750-873
2021-07-21
N/A
9.1 CRITICAL
An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to firmware update functionality. An attacker can send an authenticated HTTPS POST request to direct the Cloud Connectivity software to connect to an attacker controlled Azure IoT Hub node.
An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers as a part of executing a firmware update, potentially resulting in code execution. An attacker can create a malicious firmware update package file using any zip utility. The user must initiate a firmware update through e!COCKPIT and choose the malicious wup file using the file browser to trigger the vulnerability.
An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a newer firmware version is being installed. An attacker can create a custom firmware update package with invalid metadata in order to trigger this vulnerability.
750-830_firmware, 750-830, 750-849_firmware, 750-849, 750-871_firmware, 750-871, 750-872_firmware, 750-872, 750-873_firmware, 750-873
2020-03-18
N/A
7.2 HIGH
An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command.
750-830_firmware, 750-830, 750-849_firmware, 750-849, 750-871_firmware, 750-871, 750-872_firmware, 750-872, 750-873_firmware, 750-873
2020-03-18
N/A
7.2 HIGH
An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command.
