CVE-2018-10696: CSRF
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a web interface to allow an administrator to manage the device. However, this interface is not protected against CSRF attacks, which allows an attacker to trick an administrator into executing actions without his/her knowledge, as demonstrated by the forms/iwwebSetParameters and forms/webSetMainRestart URIs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10696?
CVE-2018-10696 is classified as a medium severity vulnerability due to CSRF attack vectors.
How do I fix CVE-2018-10696?
To fix CVE-2018-10696, it is advisable to upgrade the Moxa AWK-3121 firmware to a version that mitigates CSRF vulnerabilities.
What are the consequences of CVE-2018-10696?
The consequences of CVE-2018-10696 include unauthorized actions being executed on the device by an attacker exploiting CSRF vulnerabilities.
Which devices are affected by CVE-2018-10696?
CVE-2018-10696 affects Moxa AWK-3121 devices with firmware version 1.14.
What type of attack is associated with CVE-2018-10696?
CVE-2018-10696 is associated with Cross-Site Request Forgery (CSRF) attacks.