Database/Control plane, storage & DevOps

Moxa NPort IAW5000A-I/O serial device server: The built-in web server doesn't validate input properly, letting a remote
Impact
The built-in web server doesn't validate input properly, letting a remote unauthenticated attacker run arbitrary commands on the device server — full takeover of the box bridging serial equipment onto the network.
Who can reach it
Remote, unauthenticated — a crafted HTTP request to the web management interface is enough.
What to do
Firmware upgrade to the version Moxa published in its security advisory; requires a flash and reboot on every affected unit, which briefly drops the serial sessions it's carrying. No compensating config change exists since the flaw is in input handling, not a feature you can disable.
References
Related entries
- Grafana: Unauthenticated access to snapshots via /api/snapshots/:keyCVE-2021-39226 · GrafanaCritical
- Imagination PowerVR GPU driver - pinned memory lifecycle: An unprivileged app allocates pinned GPU memory, unpins it soCVE-2021-39815 · Imagination PowerVR GPU driver - pinned memory lifecycleCritical
- Broadcom Emulex HBA Manager / OneCommand Manager (Fibre Channel and FC-NVMe HBAs), before 11.4.425.0 and 12.8.542.31CVE-2021-42774 · Broadcom Emulex HBA Manager / OneCommand Manager (Fibre Channel and FC-NVMe HBAs), before 11.4.425.0 and 12.8.542.31Critical
- Microsoft iSNS Server service (Internet Storage Name Service for iSCSI discovery): Memory corruption in the iSNS ServerCVE-2021-43215 · Microsoft iSNS Server service (Internet Storage Name Service for iSCSI discovery)Critical
- F5 BIG-IP (iControl REST): An unauthenticated attacker can send undisclosed requests to the iControl REST managementCVE-2022-1388 · F5 BIG-IP (iControl REST)Critical
- Cisco Nexus Dashboard (web UI / CSRF): One of a batch of unauthenticated flaws in Nexus Dashboard that together allowCVE-2022-20861 · Cisco Nexus Dashboard (web UI / CSRF)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.