PT-2019-8765 · Moxa · Moxa Awk-3121

Samuel Huntley

·

Publicado

2019-06-07

·

Atualizado

2023-02-28

·

CVE-2018-10698

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa AWK-3121 version 1.14
Description An issue was discovered where the device enables an unencrypted TELNET service by default. This allows an attacker who has gained a Man-In-The-Middle (MITM) position to easily sniff the traffic between the device and the user. Additionally, an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.
Recommendations For Moxa AWK-3121 version 1.14, consider disabling the TELNET service or changing the default credentials to prevent unauthorized access. As a temporary workaround, restrict access to the TELNET daemon until a more secure configuration or patch is available.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10698

Produtos afetados

Moxa Awk-3121