PT-2021-4361 · Moxa · Moxa Mxview

Noam Moshe

·

Published

2021-10-05

·

Updated

2022-10-25

·

CVE-2021-38460

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moxa MXView versions 3.x through 3.2.2
Description The issue is related to an insecure transmission of credentials in the Moxa MXView network management software. It also involves a path traversal vulnerability that may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries, potentially leading to unauthorized access to protected information.
Recommendations For versions 3.x through 3.2.2, consider restricting access to critical files and directories to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the software for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-04991
CVE-2021-38460

Affected Products

Moxa Mxview