PT-2022-5106 · Moxa · Moxa Mxview
Patrick Desantis
·
Published
2022-02-11
·
Updated
2022-10-24
·
CVE-2021-40390
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa MXView version 3.2.4
Description
The issue is related to the use of hardcoded credentials in the web interface of Moxa MXView, allowing a remote attacker to gain full access to the device by sending a specially crafted HTTP request. This can lead to unauthorized access.
Recommendations
For Moxa MXView version 3.2.4, consider disabling the web interface functionality until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of unauthorized access. Avoid using the web application functionality in Moxa MXView until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Mxview