ID

VAR-201804-1653


CVE

CVE-2018-7506


TITLE

Moxa Mxview Information Disclosure Vulnerability

Trust: 0.8

sources: IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // CNVD: CNVD-2018-07298

DESCRIPTION

The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information. Moxa MXview Contains a cryptographic vulnerability.Information may be obtained. Moxa MXview is a network management software for monitoring and diagnosing industrial networks. An information disclosure vulnerability exists in Moxa Mxview 2.8 and earlier. The vulnerability could be exploited by a remote attacker to decrypt encrypted information. Moxa MXview is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may aid in further attacks. Moxa MXview versions 2.8 and prior are vulnerable; other versions may also be affected

Trust: 2.79

sources: NVD: CVE-2018-7506 // JVNDB: JVNDB-2018-004052 // CNVD: CNVD-2018-07298 // BID: 103722 // IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // VULHUB: VHN-137538 // VULMON: CVE-2018-7506

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // CNVD: CNVD-2018-07298

AFFECTED PRODUCTS

vendor:moxamodel:mxviewscope:lteversion:2.8

Trust: 1.8

vendor:moxamodel:mxviewscope:eqversion:2.8

Trust: 0.9

vendor:moxamodel:mxviewscope:lteversion:<=2.8

Trust: 0.8

vendor:moxamodel:mxviewscope:neversion:2.9

Trust: 0.3

sources: IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // CNVD: CNVD-2018-07298 // BID: 103722 // JVNDB: JVNDB-2018-004052 // CNNVD: CNNVD-201804-242 // NVD: CVE-2018-7506

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-7506
value: HIGH

Trust: 1.0

NVD: CVE-2018-7506
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-07298
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201804-242
value: HIGH

Trust: 0.6

IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1
value: HIGH

Trust: 0.2

VULHUB: VHN-137538
value: MEDIUM

Trust: 0.1

VULMON: CVE-2018-7506
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-7506
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2018-07298
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-137538
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-7506
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // CNVD: CNVD-2018-07298 // VULHUB: VHN-137538 // VULMON: CVE-2018-7506 // JVNDB: JVNDB-2018-004052 // CNNVD: CNNVD-201804-242 // NVD: CVE-2018-7506

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.1

problemtype:CWE-310

Trust: 0.9

sources: VULHUB: VHN-137538 // JVNDB: JVNDB-2018-004052 // NVD: CVE-2018-7506

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201804-242

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201804-242

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-004052

PATCH

title:MXviewurl:https://www.moxa.com/support/sarch_result.aspx?prod_id=622&type_id=6&type=soft

Trust: 0.8

title:Moxa Mxview Information Disclosure Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/125141

Trust: 0.6

title:Moxa Mxview Fixes for encryption problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=83085

Trust: 0.6

sources: CNVD: CNVD-2018-07298 // JVNDB: JVNDB-2018-004052 // CNNVD: CNNVD-201804-242

EXTERNAL IDS

db:NVDid:CVE-2018-7506

Trust: 3.7

db:ICS CERTid:ICSA-18-095-02

Trust: 3.5

db:BIDid:103722

Trust: 2.1

db:CNVDid:CNVD-2018-07298

Trust: 0.8

db:CNNVDid:CNNVD-201804-242

Trust: 0.8

db:JVNDBid:JVNDB-2018-004052

Trust: 0.8

db:IVDid:E2EACB9F-39AB-11E9-AD47-000C29342CB1

Trust: 0.2

db:SEEBUGid:SSVID-98983

Trust: 0.1

db:VULHUBid:VHN-137538

Trust: 0.1

db:VULMONid:CVE-2018-7506

Trust: 0.1

sources: IVD: e2eacb9f-39ab-11e9-ad47-000c29342cb1 // CNVD: CNVD-2018-07298 // VULHUB: VHN-137538 // VULMON: CVE-2018-7506 // BID: 103722 // JVNDB: JVNDB-2018-004052 // CNNVD: CNNVD-201804-242 // NVD: CVE-2018-7506

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-18-095-02

Trust: 3.6

url:http://www.securityfocus.com/bid/103722

Trust: 1.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-7506

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-7506

Trust: 0.8

url:http://www.moxastore.com/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/200.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/141255

Trust: 0.1

sources: CNVD: CNVD-2018-07298 // VULHUB: VHN-137538 // VULMON: CVE-2018-7506 // BID: 103722 // JVNDB: JVNDB-2018-004052 // CNNVD: CNNVD-201804-242 // NVD: CVE-2018-7506

CREDITS

Michael DePlante

Trust: 0.3

sources: BID: 103722

SOURCES

db:IVDid:e2eacb9f-39ab-11e9-ad47-000c29342cb1
db:CNVDid:CNVD-2018-07298
db:VULHUBid:VHN-137538
db:VULMONid:CVE-2018-7506
db:BIDid:103722
db:JVNDBid:JVNDB-2018-004052
db:CNNVDid:CNNVD-201804-242
db:NVDid:CVE-2018-7506

LAST UPDATE DATE

2024-11-23T23:12:08.675000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-07298date:2018-04-10T00:00:00
db:VULHUBid:VHN-137538date:2019-10-03T00:00:00
db:VULMONid:CVE-2018-7506date:2019-10-03T00:00:00
db:BIDid:103722date:2018-04-05T00:00:00
db:JVNDBid:JVNDB-2018-004052date:2018-06-08T00:00:00
db:CNNVDid:CNNVD-201804-242date:2019-10-23T00:00:00
db:NVDid:CVE-2018-7506date:2024-11-21T04:12:15.790

SOURCES RELEASE DATE

db:IVDid:e2eacb9f-39ab-11e9-ad47-000c29342cb1date:2018-04-10T00:00:00
db:CNVDid:CNVD-2018-07298date:2018-04-10T00:00:00
db:VULHUBid:VHN-137538date:2018-04-06T00:00:00
db:VULMONid:CVE-2018-7506date:2018-04-06T00:00:00
db:BIDid:103722date:2018-04-05T00:00:00
db:JVNDBid:JVNDB-2018-004052date:2018-06-08T00:00:00
db:CNNVDid:CNNVD-201804-242date:2018-04-06T00:00:00
db:NVDid:CVE-2018-7506date:2018-04-06T14:29:00.237