CVE-2018-10691: High severity moxa awk-3121 firmware vulnerability
An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10691?
CVE-2018-10691 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive system logs.
How do I fix CVE-2018-10691?
To fix CVE-2018-10691, update the Moxa AWK-3121 firmware to a version that addresses this vulnerability.
What type of vulnerability is CVE-2018-10691?
CVE-2018-10691 is an information disclosure vulnerability that allows unauthorized downloading of system logs.
Who is affected by CVE-2018-10691?
Devices running Moxa AWK-3121 firmware version 1.14 are affected by CVE-2018-10691.
What can an attacker do with CVE-2018-10691?
An attacker can exploit CVE-2018-10691 to download sensitive system log files without authentication or authorization.