CVE-2017-7455: Infoleak
Published Apr 14, 2017
·Updated
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
Affected Software
1 affected component
MOXA MXView=2.8
Event History
Apr 14, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7455?
CVE-2017-7455 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive private key files.
2
How do I fix CVE-2017-7455?
To mitigate CVE-2017-7455, users should upgrade to a patched version of Moxa MXView or apply specific security configurations to restrict access.
3
What are the potential risks associated with CVE-2017-7455?
The primary risk of CVE-2017-7455 is the exposure of private key material, which could lead to unauthorized interception of encrypted communications.
4
Who is affected by CVE-2017-7455?
Devices running Moxa MXView version 2.8 are directly affected by CVE-2017-7455.
5
Can CVE-2017-7455 be exploited remotely?
Yes, CVE-2017-7455 can be exploited remotely, allowing attackers to read sensitive files without authentication.