PT-2021-4364 · Moxa · Moxa Mxview

Noam Moshe

·

Published

2021-10-05

·

Updated

2022-04-25

·

CVE-2021-38456

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa MXView versions 3.x through 3.2.2
Description The issue is related to the use of hard-coded passwords in the Moxa MXView Network Management software. This could allow a remote attacker to gain unauthorized access to protected information using default passwords.
Recommendations For versions 3.x through 3.2.2, update the software to a version that does not use hard-coded passwords, or change the default passwords to custom ones to prevent exploitation. As a temporary workaround, consider disabling the use of default passwords until a patch is available. Restrict access to the software to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04994
CVE-2021-38456

Affected Products

Moxa Mxview