CVE-2018-7506: Infoleak
The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7506?
CVE-2018-7506 is a vulnerability in Moxa MXview versions 2.8 and prior that allows a remote attacker to read and access the private key of the web server via an HTTP GET request.
How severe is CVE-2018-7506?
CVE-2018-7506 has a severity score of 7.5 (High).
How can a remote attacker exploit CVE-2018-7506?
A remote attacker can exploit CVE-2018-7506 by sending an HTTP GET request to read and access the private key of the web server.
Which versions of Moxa MXview are affected by CVE-2018-7506?
Moxa MXview versions 2.8 and prior are affected by CVE-2018-7506.
Are there any references for CVE-2018-7506?
Yes, you can find references for CVE-2018-7506 at http://www.securityfocus.com/bid/103722 and https://ics-cert.us-cert.gov/advisories/ICSA-18-095-02.