PT-2021-4361 · Moxa · Moxa Mxview
Noam Moshe
·
Published
2021-10-05
·
Updated
2022-10-25
·
CVE-2021-38460
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moxa MXView versions 3.x through 3.2.2
Description
The issue is related to an insecure transmission of credentials in the Moxa MXView network management software. It also involves a path traversal vulnerability that may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries, potentially leading to unauthorized access to protected information.
Recommendations
For versions 3.x through 3.2.2, consider restricting access to critical files and directories to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using the software for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Mxview