CVE-2021-38452
published 2021-10-12CVE-2021-38452: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files…
PriorityP357critical9.1CVSS 3.1
AVNACLPRNUINSUCNIHAH
EPSS
1.55%
72.2th percentile
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxview | 3.0 – 3.2.2 | — |
| moxa | mxview_network_management_software | 3.x – 3.2.2 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXview Network Management Software
cisa_ics·2021-10-05·CVSS 7.5
[HIGH] Moxa MXview Network Management Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview Network Management Software
Last RevisedOctober 05, 2021
Alert CodeICSA-21-278-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXview Network Management Software
- Vulnerabilities: Path Traversal, Use of Hard-coded Password, Unprotected Transport of Credentials, Injection, Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to create or overwrite critical files to execute code, gain access to the program, obtain credenti
GHSA
GHSA-5xx4-5hcg-xx45: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
ghsa_unreviewed·2022-05-24
CVE-2021-38452 [CRITICAL] CWE-22 GHSA-5xx4-5hcg-xx45: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-12
Published