PT-2019-8758 · Moxa · Moxa Awk-3121

Samuel Huntley

·

Publicado

2019-06-07

·

Atualizado

2019-06-10

·

CVE-2018-10691

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moxa AWK-3121 version 1.14
Description An issue allows an attacker to download the /systemlog.log file, which is the system log, without any authentication or authorization. This is the same functionality intended for administrators to download the system log.
Recommendations For Moxa AWK-3121 version 1.14, consider restricting access to the /systemlog.log file until a patch is available. As a temporary workaround, restrict access to the API endpoint that allows downloading the system log to minimize the risk of exploitation.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10691

Produtos afetados

Moxa Awk-3121