PT-2019-8761 · Moxa · Moxa Awk-3121

Samuel Huntley

·

Publicado

2019-06-07

·

Atualizado

2023-02-28

·

CVE-2018-10694

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa AWK-3121 version 1.14
Description An issue was discovered where the device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. This allows an attacker to sniff the traffic passing between the user's computer and the device, potentially stealing credentials over HTTP and TELNET connections. Additionally, an attacker can perform a Man-in-the-Middle (MITM) attack, infecting a user's computer.
Recommendations For Moxa AWK-3121 version 1.14, consider disabling the open Wi-Fi connection until a patch or secure configuration is available. Restrict access to the device's setup process to minimize the risk of exploitation. Avoid using the device's default open Wi-Fi connection for administrative tasks.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10694

Produtos afetados

Moxa Awk-3121