CVE-2018-10690: High severity moxa awk-3121 firmware vulnerability
An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server. This allows an attacker to sniff the traffic easily and allows an attacker to compromise sensitive data such as credentials.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-10690?
CVE-2018-10690 is a vulnerability discovered on Moxa AWK-3121 1.14 devices that allows insecure communication and potential data compromise.
What is the severity of CVE-2018-10690?
The severity of CVE-2018-10690 is rated as high, with a severity value of 8.1.
How does CVE-2018-10690 affect Moxa AWK-3121 firmware 1.14?
CVE-2018-10690 affects Moxa AWK-3121 firmware 1.14 by allowing HTTP traffic, making the communication insecure and enabling potential data compromise.
How can an attacker exploit CVE-2018-10690?
An attacker can exploit CVE-2018-10690 by sniffing the insecure traffic and compromising sensitive data on the Moxa AWK-3121 device.
How can I fix CVE-2018-10690?
To fix CVE-2018-10690, it is recommended to disable HTTP traffic and use secure communication mechanisms on the Moxa AWK-3121 device.