#VU39182 Information disclosure in MXview - CVE-2017-7455

 

#VU39182 Information disclosure in MXview - CVE-2017-7455

Published: April 14, 2017 / Updated: August 9, 2020


Vulnerability identifier: #VU39182
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green
CVE-ID: CVE-2017-7455
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
MXview
Software vendor:
Moxa

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.


Remediation

Install update from vendor's website.

External links