cbcvebase.
CVE-2021-38454
published 2021-10-12

CVE-2021-38454: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files…

PriorityP274critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
15.79%
96.5th percentile
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Affected

2 ranges
VendorProductVersion rangeFixed in
moxamxview3.0 – 3.2.2
moxamxview_network_management_software3.x – 3.2.2

Detection & IOCsextracted from sources · hover to see the quote

urlapi/sites/site/*/ping
port8883
snort
alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Moxa MxView RCE Attempt (CVE-2021-38454)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"api/sites/site/"; fast_pattern; pcre:"/^[a-zA-Z0-9]{5,45}/R"; content:"/ping"; endswith; reference:cve,2021-38454; classtype:attempted-admin; sid:2035194; rev:2; metadata:attack_target Server, created_at 2022_02_14, cve CVE_2021_38454, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2022_02_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
  • Exploit traffic is HTTP POST to URI path matching pattern 'api/sites/site/<5-45 alphanumeric chars>/ping' — monitor for this pattern on internal HTTP servers.
  • CVE-2021-38454 is an Improper Access Control flaw allowing remote connections to internal MQTT communication channels; monitor for unexpected inbound connections on TCP port 8883 (MQTT over TLS).
  • Emergent Threats Snort SID 2035194 (rev:2) covers this CVE with Medium confidence at both Perimeter and Internal deployment points.
  • ·The Snort rule targets both Perimeter and Internal deployment zones, meaning the misconfigured MQTT service may be reachable from external networks as well as laterally from internal hosts — scope detection accordingly.
  • ·No known public exploits specifically target these vulnerabilities at the time of the advisory, which may affect the urgency of detection tuning.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.