cbcvebase.
CVE-2021-38458
published 2021-10-12

CVE-2021-38458: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.71%
74.6th percentile
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

Affected

2 ranges
VendorProductVersion rangeFixed in
moxamxview3.0 – 3.2.2
moxamxview_network_management_software3.x – 3.2.2

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2021-38458 is an injection vulnerability (CWE-74) in Moxa MXview Network Management Software versions 3.x to 3.2.2, allowing unauthenticated remote command execution with no user interaction required (CVSS 9.8, AV:N/AC:L/PR:N/UI:N).
  • Block or monitor port 8883 (MQTT) as the related misconfigured service (CVE-2021-38454) exposes internal MQTT communication channels remotely, which may be chained with the injection vulnerability.
  • ·No known public exploits specifically targeting CVE-2021-38458 were identified at time of advisory publication.
  • ·The vulnerability affects MXview versions 3.x through 3.2.2; version 3.2.4 and higher are patched. Detections should be scoped to unpatched deployments.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.