CVE-2017-14030
published 2018-01-12CVE-2017-14030: An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.37%
29.1th percentile
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxview | <= 2.8 | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pmxr-xmgm-6hr9: An issue was discovered in Moxa MXview v2
ghsa_unreviewed·2022-05-13
CVE-2017-14030 [HIGH] CWE-428 GHSA-pmxr-xmgm-6hr9: An issue was discovered in Moxa MXview v2
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
CISA ICS
Moxa MXview
cisa_ics·2018-01-11
Moxa MXview
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview
Last RevisedJanuary 11, 2018
Alert CodeICSA-18-011-02
## CVSS v3 7.8
ATTENTION: Low skill level to exploit.
Vendor: Moxa
Equipment: MXview
Vulnerability: Unquoted Search Path or Element.
## AFFECTED PRODUCTS
The following versions of MXview, network management software, are affected:
- MXview v2.8 and prior.
## IMPACT
Successful exploitation of this vulnerability could allow a local authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
## MITIGATION
Moxa has produced new firmware Version 2.9 for
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-01-12
Published