CVE-2015-6481
Moxa OnCell Central Manager Server RequestController Static Credentials Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The login function in the RequestController class in Moxa OnCell Central Manager before 2.2 has a hardcoded root password, which allows remote attackers to obtain administrative access via a login session.
La función de inicio de sesión en la clase RequestController en Moxa OnCell Central Manager en versiones anteriores a 2.2 tiene una contraseña de root embebida, lo que permite a atacantes remotos obtener acceso administrativo a través de un inicio de sesión.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Moxa OnCell Central Manager Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the RequestController class. The specific flaw exists within the login() function which contains hard-coded credentials. An attacker can exploit this condition to take full control of the product and achieve code execution on all managed hosts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-08-17 CVE Reserved
- 2015-09-29 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://zerodayinitiative.com/advisories/ZDI-15-453 | X_refsource_misc | |
https://ics-cert.us-cert.gov/advisories/ICSA-15-328-01 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Oncell Central Manager Search vendor "Moxa" for product "Oncell Central Manager" | <= 2.0 Search vendor "Moxa" for product "Oncell Central Manager" and version " <= 2.0" | - |
Affected
|