QID 590553

Date Published: 2021-10-22

QID 590553: Moxa MXview Network Management Software Multiple Vulnerabilities (ICSA-21-278-03)

AFFECTED PRODUCTS
The following versions of MXview, a network management software, are affected:
MXview Network Management Software: Versions 3.x to 3.2.2

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of these vulnerabilities may allow an attacker to create or overwrite critical files to execute code, gain access to the program, obtain credentials, disable the software, read and modify otherwise inaccessible data, allow remote connections to internal communication channels, or interact and use MQTT remotely.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-278-03 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-278-03 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-278-03