Vulnerable Assets Library

A searchable database of maritime OT equipment with known vulnerabilities — covering navigation systems, engine automation, power management, and vessel control CBS from major marine vendors. Search by vendor, product family, or CVE ID to check whether equipment on your vessel has documented vulnerabilities requiring attention or patch management action.

Searchable by vendor CVE referenced Marine OT vendors Continuously updated
Audit Level: Tactical
Records optimised: 01.07.2026 16:57 UTC

CVE-2026-0714 — Moxa: UC-1200A Series

Published: 2026-02-05 | Updated: 2026-02-05

HIGH 7
A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attaching external equipment to the SPI bus to capture TPM communications. If successful, the captured data may allow offline decryption of eMMC contents. This attack cannot be performed through brief or opportunistic physical access and requires extended physical access, possession of the device, appropriate equipment, and sufficient time for signal capture and analysis. Remote exploitation is not possible.

CVSS VECTOR: CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

NVD Record ↗ | Vendor Advisory / Fix ↗

← Back to full Vulnerable Assets Library

Get new CVE entries like these in your inbox weekly. Subscribe →

Disclaimer & Methodology

The Marine OT Vulnerable Assets Library is a curated repository of security advisories identified through automated heuristic filtering. Users should verify hardware revisions with manufacturers before patching.

Scroll to Top