PT-2022-5106 · Moxa · Moxa Mxview

Patrick Desantis

·

Published

2022-02-11

·

Updated

2022-10-24

·

CVE-2021-40390

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa MXView version 3.2.4
Description The issue is related to the use of hardcoded credentials in the web interface of Moxa MXView, allowing a remote attacker to gain full access to the device by sending a specially crafted HTTP request. This can lead to unauthorized access.
Recommendations For Moxa MXView version 3.2.4, consider disabling the web interface functionality until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of unauthorized access. Avoid using the web application functionality in Moxa MXView until the issue is resolved.

Exploit

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-06352
CVE-2021-40390

Affected Products

Moxa Mxview