Hardcoded Root Password Vulnerability in Moxa OnCell Central Manager
CVE-2015-6481

8.3HIGH

Key Information:

Vendor
Moxa
Vendor
CVE Published:
21 December 2015

Summary

The RequestController class in Moxa OnCell Central Manager, prior to version 2.2, contains a hardcoded root password. This security flaw enables remote attackers to gain unauthorized administrative access through an active login session. As such, organizations utilizing affected versions are at significant risk of compromised systems, leading to potential data breaches and loss of control over the device functionalities. It is imperative for users to update to recommended versions to mitigate this vulnerability.

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.