cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2018-5455,https://securityvulnerability.io/vulnerability/CVE-2018-5455,,"A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.",Moxa,Moxa Oncell G3100-hspa Series,9.8,CRITICAL,0.0019399999873712659,false,,false,false,false,,,false,false,,2018-03-05T17:00:00.000Z,0 CVE-2018-5449,https://securityvulnerability.io/vulnerability/CVE-2018-5449,,"A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application does not check for a NULL value, allowing for an attacker to perform a denial of service attack.",Moxa,Moxa Oncell G3100-hspa Series,6.5,MEDIUM,0.000590000010561198,false,,false,false,false,,,false,false,,2018-03-05T17:00:00.000Z,0 CVE-2018-5453,https://securityvulnerability.io/vulnerability/CVE-2018-5453,,"An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.",Moxa,Moxa Oncell G3100-hspa Series,7.5,HIGH,0.0011099999537691474,false,,false,false,false,,,false,false,,2018-03-05T17:00:00.000Z,0 CVE-2017-7913,https://securityvulnerability.io/vulnerability/CVE-2017-7913,,"A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application's configuration file contains parameters that represent passwords in plaintext.",Moxa,Moxa Oncell,9.8,CRITICAL,0.0017600000137463212,false,,false,false,false,,,false,false,,2017-05-29T16:00:00.000Z,0 CVE-2017-7915,https://securityvulnerability.io/vulnerability/CVE-2017-7915,,"An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. An attacker can freely use brute force to determine parameters needed to bypass authentication.",Moxa,Moxa Oncell,9.8,CRITICAL,0.0023499999660998583,false,,false,false,false,,,false,false,,2017-05-29T16:00:00.000Z,0 CVE-2017-7917,https://securityvulnerability.io/vulnerability/CVE-2017-7917,,"A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.",Moxa,Moxa Oncell,8.8,HIGH,0.0008299999753944576,false,,false,false,false,,,false,false,,2017-05-29T16:00:00.000Z,0 CVE-2016-8362,https://securityvulnerability.io/vulnerability/CVE-2016-8362,,"An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. Any user is able to download log files by accessing a specific URL.",Moxa,Moxa Oncell,6.5,MEDIUM,0.0005799999926239252,false,,false,false,false,,,false,false,,2017-02-13T21:00:00.000Z,0 CVE-2016-8363,https://securityvulnerability.io/vulnerability/CVE-2016-8363,,"An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. User is able to execute arbitrary OS commands on the server.",Moxa,Moxa Oncell,10,CRITICAL,0.001979999942705035,false,,false,false,false,,,false,false,,2017-02-13T21:00:00.000Z,0