Severity
7.8HIGH
EPSS
0.0%
top 91.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 5
Latest updateMay 24

Description

An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewService, which starts as a NT SYSTEM authority user executes a series of Node.Js scripts to start additional application functionality.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDmoxa/mxview3.1.8
CVEListV5moxaMoxa MXView Series 3.1.8

🔴Vulnerability Details

2
GHSA
GHSA-f9j2-hv33-h2gp: An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 32022-05-24
CVEList
CVE-2020-13536: An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 32020-11-05
CVE-2020-13536 (HIGH CVSS 7.8) | An exploitable local privilege elev | cvebase.io