PT-2022-5105 · Moxa · Moxa Mxview
Patrick Desantis
·
Published
2022-02-11
·
Updated
2022-04-22
·
CVE-2021-40392
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moxa MXView version 3.2.4
Description
The issue is related to the transmission of data in an open manner, which can allow a remote attacker to disclose protected information. An information disclosure vulnerability exists in the Web Application functionality, where network sniffing can lead to the disclosure of sensitive information. An attacker can exploit this vulnerability by sniffing network traffic.
Recommendations
For Moxa MXView version 3.2.4, consider restricting access to sensitive information and network traffic to minimize the risk of exploitation. As a temporary workaround, restrict network access to the Web Application functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Mxview