Security Advisory
CVE-2015-6480
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The MessageBrokerServlet servlet in Moxa OnCell Central Manager before 2.2 does not require authentication, which allows remote attackers to obtain administrative access via a command, as demonstrated by the addUserAndGroup action.