cbcvebase.
CVE-2018-7506
published 2018-04-06

CVE-2018-7506: The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote…

PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.97%
78.1th percentile
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

Affected

2 ranges
VendorProductVersion rangeFixed in
ics-certmoxa_mxview
moxamxview<= 2.8

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.