CVE-2021-38456
published 2021-10-12CVE-2021-38456: A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.11%
62.2th percentile
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxview | 3.0 – 3.2.2 | — |
| moxa | mxview_network_management_software | 3.x – 3.2.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Block or monitor Port 8883 (MQTT) to detect/prevent exploitation of the improper access control vulnerability (CVE-2021-38454) that allows remote connections to internal MQTT communication channels, which is co-located with CVE-2021-38456 in the same affected product. ↗
- ·CVE-2021-38456 is a hard-coded password vulnerability in Moxa MXview versions 3.x through 3.2.2. The hard-coded credentials are not publicly disclosed in the available sources, but any authentication attempt using default/hard-coded passwords against MXview services should be treated as suspicious. ↗
- ·No known public exploits specifically targeting CVE-2021-38456 (or the related MXview vulnerabilities) were identified at the time of advisory publication. ↗
- ·Affected versions are MXview Network Management Software 3.x to 3.2.2; patched version is 3.2.4 or higher. Detection efforts should focus on unpatched deployments. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXview Network Management Software
cisa_ics·2021-10-05·CVSS 7.5
[HIGH] Moxa MXview Network Management Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview Network Management Software
Last RevisedOctober 05, 2021
Alert CodeICSA-21-278-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXview Network Management Software
- Vulnerabilities: Path Traversal, Use of Hard-coded Password, Unprotected Transport of Credentials, Injection, Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to create or overwrite critical files to execute code, gain access to the program, obtain credenti
GHSA
GHSA-rqhq-r7rw-cwjc: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
ghsa_unreviewed·2022-05-24
CVE-2021-38456 [CRITICAL] CWE-259 GHSA-rqhq-r7rw-cwjc: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-12
Published