CVE-2021-38454
published 2021-10-12CVE-2021-38454: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files…
PriorityP274critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
15.79%
96.5th percentile
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxview | 3.0 – 3.2.2 | — |
| moxa | mxview_network_management_software | 3.x – 3.2.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
urlapi/sites/site/*/ping
snort
alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"api/sites/site/"; fast_pattern; pcre:"/^[a-zA-Z0-9]{5,45}/R"; content:"/ping"; endswith; reference:cve,2021-38454; classtype:attempted-admin; sid:2035194; rev:2; metadata:attack_target Server, created_at 2022_02_14, cve CVE_2021_38454, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2022_02_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)- →Exploit traffic is HTTP POST to URI path matching pattern 'api/sites/site/<5-45 alphanumeric chars>/ping' — monitor for this pattern on internal HTTP servers.
- →CVE-2021-38454 is an Improper Access Control flaw allowing remote connections to internal MQTT communication channels; monitor for unexpected inbound connections on TCP port 8883 (MQTT over TLS). ↗
- →Emergent Threats Snort SID 2035194 (rev:2) covers this CVE with Medium confidence at both Perimeter and Internal deployment points.
- ·The Snort rule targets both Perimeter and Internal deployment zones, meaning the misconfigured MQTT service may be reachable from external networks as well as laterally from internal hosts — scope detection accordingly.
- ·No known public exploits specifically target these vulnerabilities at the time of the advisory, which may affect the urgency of detection tuning. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXview Network Management Software
cisa_ics·2021-10-05·CVSS 7.5
[HIGH] Moxa MXview Network Management Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview Network Management Software
Last RevisedOctober 05, 2021
Alert CodeICSA-21-278-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXview Network Management Software
- Vulnerabilities: Path Traversal, Use of Hard-coded Password, Unprotected Transport of Credentials, Injection, Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to create or overwrite critical files to execute code, gain access to the program, obtain credenti
GHSA
GHSA-x75v-mvrc-2f88: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
ghsa_unreviewed·2022-05-24
CVE-2021-38454 [CRITICAL] CWE-22 GHSA-x75v-mvrc-2f88: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Suricata
ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)
suricata·2022-02-14·CVSS 10.0
CVE-2021-38454 [CRITICAL] ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)
ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"api/sites/site/"; fast_pattern; pcre:"/^[a-zA-Z0-9]{5,45}/R"; content:"/ping"; endswith; reference:cve,2021-38454; classtype:attempted-admin; sid:2035194; rev:2; metadata:attack_target Server, created_at 2022_02_14, cve CVE_2021_38454, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2022_02_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
No public exploits indexed.
No writeups or analysis indexed.
2021-10-12
Published