PT-2019-8758 · Moxa · Moxa Awk-3121

Samuel Huntley

·

Published

2019-06-07

·

Updated

2019-06-10

·

CVE-2018-10691

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moxa AWK-3121 version 1.14
Description An issue allows an attacker to download the /systemlog.log file, which is the system log, without any authentication or authorization. This is the same functionality intended for administrators to download the system log.
Recommendations For Moxa AWK-3121 version 1.14, consider restricting access to the /systemlog.log file until a patch is available. As a temporary workaround, restrict access to the API endpoint that allows downloading the system log to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10691

Affected Products

Moxa Awk-3121