PT-2019-8761 · Moxa · Moxa Awk-3121
Samuel Huntley
·
Published
2019-06-07
·
Updated
2023-02-28
·
CVE-2018-10694
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3121 version 1.14
Description
An issue was discovered where the device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. This allows an attacker to sniff the traffic passing between the user's computer and the device, potentially stealing credentials over HTTP and TELNET connections. Additionally, an attacker can perform a Man-in-the-Middle (MITM) attack, infecting a user's computer.
Recommendations
For Moxa AWK-3121 version 1.14, consider disabling the open Wi-Fi connection until a patch or secure configuration is available. Restrict access to the device's setup process to minimize the risk of exploitation. Avoid using the device's default open Wi-Fi connection for administrative tasks.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Awk-3121