CVE-2021-38458
published 2021-10-12CVE-2021-38458: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.71%
74.6th percentile
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mxview | 3.0 – 3.2.2 | — |
| moxa | mxview_network_management_software | 3.x – 3.2.2 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-38458 is an injection vulnerability (CWE-74) in Moxa MXview Network Management Software versions 3.x to 3.2.2, allowing unauthenticated remote command execution with no user interaction required (CVSS 9.8, AV:N/AC:L/PR:N/UI:N). ↗
- →Block or monitor port 8883 (MQTT) as the related misconfigured service (CVE-2021-38454) exposes internal MQTT communication channels remotely, which may be chained with the injection vulnerability. ↗
- ·No known public exploits specifically targeting CVE-2021-38458 were identified at time of advisory publication. ↗
- ·The vulnerability affects MXview versions 3.x through 3.2.2; version 3.2.4 and higher are patched. Detections should be scoped to unpatched deployments. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MXview Network Management Software
cisa_ics·2021-10-05·CVSS 7.5
[HIGH] Moxa MXview Network Management Software
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MXview Network Management Software
Last RevisedOctober 05, 2021
Alert CodeICSA-21-278-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Moxa
- Equipment: MXview Network Management Software
- Vulnerabilities: Path Traversal, Use of Hard-coded Password, Unprotected Transport of Credentials, Injection, Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow an attacker to create or overwrite critical files to execute code, gain access to the program, obtain credenti
GHSA
GHSA-wvqc-pm32-wjgx: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
ghsa_unreviewed·2022-05-24
CVE-2021-38458 [CRITICAL] CWE-74 GHSA-wvqc-pm32-wjgx: A path traversal vulnerability in the Moxa MXview Network Management software Versions 3
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-12
Published