ID

VAR-201810-0715


CVE

CVE-2018-18394


TITLE

Moxa ThingsPro IIoT Gateway and Device Management Software Solutions Vulnerable to information disclosure

Trust: 0.8

sources: JVNDB: JVNDB-2018-011099

DESCRIPTION

Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1. An attacker could use this vulnerability to recover an access token

Trust: 2.79

sources: NVD: CVE-2018-18394 // JVNDB: JVNDB-2018-011099 // CNVD: CNVD-2018-21512 // CNNVD: CNNVD-201810-1101 // VULHUB: VHN-128949

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-21512

AFFECTED PRODUCTS

vendor:moxamodel:thingsproscope:eqversion:2.1

Trust: 3.0

sources: CNVD: CNVD-2018-21512 // JVNDB: JVNDB-2018-011099 // CNNVD: CNNVD-201810-1101 // NVD: CVE-2018-18394

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-18394
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-18394
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2018-21512
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201810-1101
value: CRITICAL

Trust: 0.6

VULHUB: VHN-128949
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-18394
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-21512
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-128949
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-18394
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-21512 // VULHUB: VHN-128949 // JVNDB: JVNDB-2018-011099 // CNNVD: CNNVD-201810-1101 // NVD: CVE-2018-18394

PROBLEMTYPE DATA

problemtype:CWE-312

Trust: 1.1

problemtype:CWE-200

Trust: 0.9

sources: VULHUB: VHN-128949 // JVNDB: JVNDB-2018-011099 // NVD: CVE-2018-18394

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201810-1101

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201810-1101

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-011099

PATCH

title:ThingsProurl:https://www.moxa.com/product/ThingsPro.htm

Trust: 0.8

title:Patch for Moxa ThingsPro weak crypto vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/142993

Trust: 0.6

title:Moxa ThingsPro Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86226

Trust: 0.6

sources: CNVD: CNVD-2018-21512 // JVNDB: JVNDB-2018-011099 // CNNVD: CNNVD-201810-1101

EXTERNAL IDS

db:NVDid:CVE-2018-18394

Trust: 3.1

db:JVNDBid:JVNDB-2018-011099

Trust: 0.8

db:CNNVDid:CNNVD-201810-1101

Trust: 0.7

db:VULDBid:125812

Trust: 0.6

db:CNVDid:CNVD-2018-21512

Trust: 0.6

db:VULHUBid:VHN-128949

Trust: 0.1

sources: CNVD: CNVD-2018-21512 // VULHUB: VHN-128949 // JVNDB: JVNDB-2018-011099 // CNNVD: CNNVD-201810-1101 // NVD: CVE-2018-18394

REFERENCES

url:https://ics-cert.kaspersky.com/advisories/klcert-advisories/2018/10/18/klcert-18-022-moxa-thingspro-iiot-gateway-and-device-management-software-solutions-sensitive-information-stored-in-clear-text/

Trust: 2.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-18394

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-18394

Trust: 0.8

url:https://vuldb.com/?id.125812

Trust: 0.6

sources: CNVD: CNVD-2018-21512 // VULHUB: VHN-128949 // JVNDB: JVNDB-2018-011099 // CNNVD: CNNVD-201810-1101 // NVD: CVE-2018-18394

SOURCES

db:CNVDid:CNVD-2018-21512
db:VULHUBid:VHN-128949
db:JVNDBid:JVNDB-2018-011099
db:CNNVDid:CNNVD-201810-1101
db:NVDid:CVE-2018-18394

LAST UPDATE DATE

2024-11-23T22:51:59.070000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-21512date:2018-10-23T00:00:00
db:VULHUBid:VHN-128949date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-011099date:2019-01-07T00:00:00
db:CNNVDid:CNNVD-201810-1101date:2019-10-23T00:00:00
db:NVDid:CVE-2018-18394date:2024-11-21T03:55:51.897

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-21512date:2018-10-23T00:00:00
db:VULHUBid:VHN-128949date:2018-10-19T00:00:00
db:JVNDBid:JVNDB-2018-011099date:2019-01-07T00:00:00
db:CNNVDid:CNNVD-201810-1101date:2018-10-22T00:00:00
db:NVDid:CVE-2018-18394date:2018-10-19T14:29:00.620