{"api_version":"1","generated_at":"2026-07-23T11:08:21+00:00","cve":"CVE-2017-14030","urls":{"html":"https://cve.report/CVE-2017-14030","api":"https://cve.report/api/cve/CVE-2017-14030.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14030","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14030"},"summary":{"title":"CVE-2017-14030","description":"An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2018-01-12 20:29:00","updated_at":"2019-10-09 23:23:00"},"problem_types":["CWE-428"],"metrics":[],"references":[{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02","name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Moxa MXview | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102494","name":"102494","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Moxa MXview CVE-2017-14030 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14030","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14030","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14030","vulnerable":"1","versionEndIncluding":"2.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moxa","cpe5":"mxview","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"ics-cert@hq.dhs.gov","ID":"CVE-2017-14030","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Moxa MXview","version":{"version_data":[{"version_value":"Moxa MXview"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-428"}]}]},"references":{"reference_data":[{"name":"102494","refsource":"BID","url":"http://www.securityfocus.com/bid/102494"},{"name":"https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02","refsource":"MISC","url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02"}]}},"nvd":{"publishedDate":"2018-01-12 20:29:00","lastModifiedDate":"2019-10-09 23:23:00","problem_types":["CWE-428"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moxa:mxview:*:*:*:*:*:*:*:*","versionEndIncluding":"2.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14030","Ordinal":"111455","Title":"CVE-2017-14030","CVE":"CVE-2017-14030","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14030","Ordinal":"1","NoteData":"An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"14030","Ordinal":"2","NoteData":"2018-01-12","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14030","Ordinal":"3","NoteData":"2018-01-13","Type":"Other","Title":"Modified"}]}}}