CVE-2015-6480
Moxa OnCell Central Manager Server MessageBrokerServlet Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.
El servlet MessageBrokerServlet en Moxa OnCell Central Manager en versiones anteriores a 2.2 no requiere autenticación, lo que permite a atacantes remotos obtener acceso administrativo a través de un comando, según lo demostrado por la acción addUserAndGroup.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Moxa OnCell Central Manager Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the MessageBrokerServlet servlet, which does not ensure a user is authenticated prior to accepting commands. An attacker can exploit this condition to perform various actions, including addUserAndGroup, to take full control of the product and achieve code execution on all managed hosts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-08-17 CVE Reserved
- 2015-09-29 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://zerodayinitiative.com/advisories/ZDI-15-452 | X_refsource_misc | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-328-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Oncell Central Manager Search vendor "Moxa" for product "Oncell Central Manager" | <= 2.0 Search vendor "Moxa" for product "Oncell Central Manager" and version " <= 2.0" | - |
Affected
|