CVE-2018-7506
published 2018-04-06CVE-2018-7506: The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.97%
78.1th percentile
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ics-cert | moxa_mxview | — | — |
| moxa | mxview | <= 2.8 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXview
cisa_ics·2018-04-05·CVSS 7.5
[HIGH] Moxa MXview
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview
Last RevisedApril 05, 2018
Alert CodeICSA-18-095-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low skill level to exploit.
- Vendor: Moxa
- Equipment: MXview
- Vulnerabilities: Information Exposure
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a remote attacker to access and read cryptographic private keys.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of MXview, network management software, are affected:
- MXview versions 2.8 and prior.
## 3.2 VULNERABILITY OVERVIEW
GHSA
GHSA-3h32-9hq6-4rcq: The private key of the web server in Moxa MXview versions 2
ghsa_unreviewed·2022-05-13
CVE-2018-7506 [HIGH] CWE-200 GHSA-3h32-9hq6-4rcq: The private key of the web server in Moxa MXview versions 2
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-04-06
Published