CVE-2018-7506

HIGH

Moxa MXview < 2.8 - Unauthenticated Exposure of Sensitive Information via HTTP GET Request

Title source: llm
STIX 2.1

Description

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103722
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-095-02

Scores

CVSS v3 7.5
EPSS 0.0108
EPSS Percentile 78.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
moxa/mxview < 2.8
Published Apr 06, 2018
Tracked Since Feb 18, 2026