Database/Control plane, storage & DevOps

Moxa NPort W2150A / W2250A wireless device server: The device ships with an empty default password, so anyone who can
Impact
The device ships with an empty default password, so anyone who can reach it on the network can log in as an unauthorized user with no credential at all and take over the serial device server.
Who can reach it
No authentication required — just network reachability to a device still running the default (blank) password.
What to do
Firmware upgrade past 1.11 plus setting a real administrator password on every device — the firmware fix stops shipping the box in an unauthenticated state, but existing deployed units also need someone to actually set a password during the upgrade. Track this as a fleet-wide credential-rotation project, not just a flash.
References
Related entries
- Moxa NPort W2150A / W2250A wireless device server: A remote attacker can crash or potentially gain code executionCVE-2024-1220 · Moxa NPort W2150A / W2250A wireless device serverHigh
- Brocade Fabric OS (proxy service information disclosure): Unauthenticated remote attackers can obtain sensitiveCVE-2018-6440 · Brocade Fabric OS (proxy service information disclosure)Critical
- IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1: Unauthorized access to user data, or injection ofCVE-2020-4926 · IBM Spectrum Scale 5.1 core / IBM Elastic Storage System 6.1Critical
- Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APICCVE-2021-1577 · Cisco APIC / Cloud APIC (API endpoint)Critical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: Path traversal to remote code executionCVE-2021-22794 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
- Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and prior: OS command injection over the networkCVE-2021-22795 · Schneider Electric StruxureWare Data Center Expert (DCE) v7.8.1 and priorCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.