PT-2022-5105 · Moxa · Moxa Mxview

Patrick Desantis

·

Published

2022-02-11

·

Updated

2022-04-22

·

CVE-2021-40392

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moxa MXView version 3.2.4
Description The issue is related to the transmission of data in an open manner, which can allow a remote attacker to disclose protected information. An information disclosure vulnerability exists in the Web Application functionality, where network sniffing can lead to the disclosure of sensitive information. An attacker can exploit this vulnerability by sniffing network traffic.
Recommendations For Moxa MXView version 3.2.4, consider restricting access to sensitive information and network traffic to minimize the risk of exploitation. As a temporary workaround, restrict network access to the Web Application functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06351
CVE-2021-40392

Affected Products

Moxa Mxview