CVE-2018-18395: Critical severity moxa thingspro vulnerability
Published Oct 19, 2018
·Updated
Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
Affected Software
1 affected component
MOXA ThingsPro=2.1
Event History
Oct 19, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-18395?
CVE-2018-18395 is classified as a medium severity vulnerability.
2
How do I fix CVE-2018-18395?
To mitigate CVE-2018-18395, upgrade Moxa ThingsPro IIoT Gateway and Device Management Software to version 2.1 or apply available security patches.
3
What type of vulnerability is CVE-2018-18395?
CVE-2018-18395 is a hidden token access vulnerability that allows unauthorized access to sensitive functions.
4
Which Moxa software versions are affected by CVE-2018-18395?
CVE-2018-18395 specifically affects Moxa ThingsPro version 2.1.
5
Can CVE-2018-18395 lead to data exposure?
Yes, CVE-2018-18395 can potentially lead to unauthorized data exposure due to hidden token access.