First published: Fri Jun 07 2019(Updated: )
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Awk-3121 Firmware | =1.14 | |
Moxa AWK-3121 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10690 is a vulnerability discovered on Moxa AWK-3121 1.14 devices that allows insecure communication and potential data compromise.
The severity of CVE-2018-10690 is rated as high, with a severity value of 8.1.
CVE-2018-10690 affects Moxa AWK-3121 firmware 1.14 by allowing HTTP traffic, making the communication insecure and enabling potential data compromise.
An attacker can exploit CVE-2018-10690 by sniffing the insecure traffic and compromising sensitive data on the Moxa AWK-3121 device.
To fix CVE-2018-10690, it is recommended to disable HTTP traffic and use secure communication mechanisms on the Moxa AWK-3121 device.