Vulnerabilities (CVE)

Filtered by vendor Moxa
Filtered by product Uc-3430a-t-lte-wifi
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-0714 1 Moxa 70 Uc-1222a, Uc-1222a Firmware, Uc-2222a-t and 67 more 2026-02-18 N/A 6.8 MEDIUM
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or oppor ...

Show More

CVE-2026-0715 1 Moxa 70 Uc-1222a, Uc-1222a Firmware, Uc-2222a-t and 67 more 2026-02-18 N/A 6.8 MEDIUM
Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu does not allow full system takeover or privilege escalation. The bootloader enforces digital signature verification and only permits flashing of Moxa-signed images. As a result, an attacker cannot install ...

Show More