HIGH🇵🇱 Wersja polska

CVE-2018-10691

CVSS 7.5v3.0pub. 2019-06-07upd. 2024-11-21

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /systemlog.log (the system log). However, the same functionality allows an attacker to download the file without any authentication or authorization.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Moxa Awk 3121

    HW
    Moxa
    all versions
  • Moxa Awk 3121 Firmware

    OS
    Moxa
    1.14
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2018-10698CRITICAL9.8PL ✓same product

Moxa AWK-3121: Niezaszyfrowana usługa TELNET z domyślnymi danymi logowania

CVE-2018-10693HIGH8.8same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator...

CVE-2018-10694HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and...

CVE-2018-10695HIGH8.8same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrato...

CVE-2018-10690HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providin...