CVE-2018-18395
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
In short
A security flaw in Moxa ThingsPro version 2.1 allows attackers to access hidden authentication tokens that should be protected. This could let someone bypass security controls and gain unauthorized access to the system.
Technical detail
CVE-2018-18395 involves improper protection of authentication tokens in Moxa ThingsPro IIoT Gateway 2.1, enabling attackers with local or network access to retrieve hidden tokens and potentially escalate privileges or bypass authentication mechanisms. The vulnerability stems from insufficient token obfuscation or encryption, allowing direct token extraction from the software.
Summary generated and translated by AI from the official description.
Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.