Moog manufactures aerospace and defense control systems, with its vulnerability footprint concentrated in the EXVF and EXVP firmware and controller product lines. The observed disclosures center on command-injection, XML external-entity, authentication-bypass, and hard-coded-credential weaknesses that are characteristic of embedded control interfaces with limited input sanitization and weak access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moog over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24054CRITICAL The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time inte | Aug 21, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-24051CRITICAL The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. I | Aug 21, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-24052CRITICAL Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Docum | Aug 21, 2020 | 9.1 | 27 | NO | NO |
CVE-2020-24053HIGH Moog EXO Series EXVF5C-2 and EXVP7C2-3 units have a hardcoded credentials vulnerability. This could cause a confidentiality issue when using the FTP, Telnet, or SSH protocols. | Aug 21, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moog.
Media articles that mention a CVE ID that affects a product developed by Moog — matched by CVE ID, not by vendor name.