CVE-2021-38456: Moxa MXview Network Management Software
A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Moxa MXview Network Management softwareto a version that resolves this vulnerability.Fixed in 3.2.4 - Configuration
If hard-coded password access is not required, use a firewall to assign/restrict the Accessible IP of MXview at the client site.
Firewall Accessible IP of MXview at the client site = Restrict to the MXview Accessible IP at the client site - Configuration
If multiple-site function is needed, use a firewall to block Port 8883.
Firewall Port blocking = Block TCP/8883 - Operational
Change the Windows password regularly and use a firewall.
Event History
Frequently Asked Questions
What is CVE-2021-38456?
CVE-2021-38456 is a use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2.
How severe is CVE-2021-38456?
CVE-2021-38456 has a severity rating of 9.8 (critical).
What is affected by CVE-2021-38456?
Moxa MXview Network Management software Versions 3.x to 3.2.2 are affected by CVE-2021-38456.
How can an attacker exploit CVE-2021-38456?
An attacker can exploit CVE-2021-38456 by gaining access through accounts using default passwords.
Is there a fix available for CVE-2021-38456?
Yes, it is recommended to update to a version higher than 3.2.2 to fix CVE-2021-38456.