|
219381
|
7.2 |
HIGH
Network
|
moxa
|
awk-3131a_firmware
|
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cau…
|
CWE-78
OS Command
|
CVE-2019-5142
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219382
|
8.8 |
HIGH
Network
|
moxa
|
awk-3131a_firmware
|
An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be re…
|
CWE-78
OS Command
|
CVE-2019-5141
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219383
|
8.8 |
HIGH
Network
|
moxa
|
awk-3131a_firmware
|
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to …
|
CWE-78
OS Command
|
CVE-2019-5140
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219384
|
7.1 |
HIGH
Local
|
moxa
|
awk-3131a_firmware
|
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encrypti…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-5139
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219385
|
9.9 |
CRITICAL
Network
|
moxa
|
awk-3131a_firmware
|
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause ar…
|
CWE-78
OS Command
|
CVE-2019-5138
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219386
|
7.5 |
HIGH
Network
|
moxa
|
awk-3131a_firmware
|
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2019-5137
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219387
|
8.8 |
HIGH
Network
|
moxa
|
awk-3131a_firmware
|
An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape fro…
|
NVD-CWE-noinfo
|
CVE-2019-5136
|
2024-11-21 13:44 |
2020-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219388
|
4.3 |
MEDIUM
Network
|
ibm
|
maximo_asset_management maximo_for_life_sciences maximo_for_transportation maximo_for_oil_and_gas maximo_for_aviation maximo_for_utilities maximo_for_nuclear_power
|
IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated user due to disclosing path information in the URL. IBM X-Force ID: 172883.
|
CWE-863
Incorrect Authorization
|
CVE-2019-4745
|
2024-11-21 13:44 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219389
|
5.3 |
MEDIUM
Adjacent
|
ibm
|
spectrum_protect_plus
|
IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacker with intimate knowledge of the system to obtain highly sensitive information.
|
NVD-CWE-noinfo
|
CVE-2019-4703
|
2024-11-21 13:44 |
2020-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219390
|
8.8 |
HIGH
Network
|
ibm
|
emptoris_spend_analysis emptoris_strategic_supply_management_platform
|
IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s…
|
CWE-89
SQL Injection
|
CVE-2019-4752
|
2024-11-21 13:44 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|