PT-2021-4362 · Moxa · Moxa Mxview
Noam Moshe
·
Published
2021-10-05
·
Updated
2022-02-14
·
CVE-2021-38458
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa MXView versions 3.x through 3.2.2
Description
The issue is related to a path traversal vulnerability in the Moxa MXView Network Management software. This vulnerability may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries, by sending a specially crafted request. The vulnerability can be exploited remotely.
Recommendations
For versions 3.x through 3.2.2, update to a version that fixes the path traversal vulnerability to prevent attackers from creating or overwriting critical files.
As a temporary workaround, consider restricting access to critical files and directories to minimize the risk of exploitation.
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Mxview