PT-2021-4364 · Moxa · Moxa Mxview
Noam Moshe
·
Published
2021-10-05
·
Updated
2022-04-25
·
CVE-2021-38456
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa MXView versions 3.x through 3.2.2
Description
The issue is related to the use of hard-coded passwords in the Moxa MXView Network Management software. This could allow a remote attacker to gain unauthorized access to protected information using default passwords.
Recommendations
For versions 3.x through 3.2.2, update the software to a version that does not use hard-coded passwords, or change the default passwords to custom ones to prevent exploitation.
As a temporary workaround, consider disabling the use of default passwords until a patch is available.
Restrict access to the software to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Mxview