PT-2020-4509 · Moxa+1 · Moxa Mxview+1

Yuri Kramarz

·

Published

2020-11-03

·

Updated

2022-06-07

·

CVE-2020-13536

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa MXView version 3.1.8
Description The issue is related to incorrect default access control settings in Moxa MXView, allowing an attacker to exploit a local privilege elevation vulnerability. This can enable the execution of arbitrary commands with system user privileges. The vulnerability exists in the file system permissions of the Moxa MXView series installation, specifically affecting the MXViewService, which runs as a NT SYSTEM authority user and executes Node.js scripts to start additional application functionality. An attacker can potentially add code to a script or replace a binary, depending on the chosen vector.
Recommendations For Moxa MXView version 3.1.8, consider restricting access to the MXViewService to minimize the risk of exploitation until a patch is available. As a temporary workaround, disabling the execution of Node.js scripts by MXViewService may help mitigate the issue. However, the most effective resolution would be to update the access control settings to prevent unauthorized access and command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05058
CVE-2020-13536

Affected Products

Moxa Mxview
Node.Js