← back
CVE-2021-38452highCWE-22

Moxa MXview Network Management Software

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.7%
exploitation probability
1.7%top 26% of all CVEs
observed exploitation
nono source reports it
In short

Moxa MXview Network Management Software has a flaw that allows attackers to create or overwrite critical files on the system, potentially enabling them to execute malicious code. This happens because the software doesn't properly validate file paths, allowing attackers to access directories they shouldn't.

Technical detail

A path traversal vulnerability (CWE-22) in Moxa MXview 3.x through 3.2.2 permits unauthenticated or low-privileged attackers to create or overwrite arbitrary files in protected directories by manipulating file path inputs. Exploitation could result in arbitrary code execution through overwriting executables or libraries, with a CVSS score of 7.5 indicating high severity.

Summary generated and translated by AI from the official description.
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N