CVE-2018-10694
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default. An administrator who uses the open wireless connection to set up the device can allow an attacker to sniff the traffic passing between the user's computer and the device. This can allow an attacker to steal the credentials passing over the HTTP connection as well as TELNET traffic. Also an attacker can MITM the response and infect a user's computer very easily as well.
Fue encontrado un problema en los dispositivos Moxa AWK-3121 versión 1.14. El dispositivo proporciona una conexión Wi-Fi que está abierta y no usa ningún mecanismo de cifrado por defecto. Un administrador que utiliza la conexión inalámbrica abierta para configurar el dispositivo puede permitir que un atacante espiar el tráfico que pasa entre el equipo del usuario y el dispositivo. Esto puede permitir que un atacante hurtar las credenciales que pasan sobre la conexión HTTP, así como el tráfico TELNET. También un atacante puede activar un ataque MITM sobre la respuesta e infectar el ordenador de un usuario fácilmente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-03 CVE Reserved
- 2019-06-07 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-311: Missing Encryption of Sensitive Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/samuelhuntley/Moxa_AWK_1121/blob/master/Moxa_AWK_1121 | Third Party Advisory | |
https://seclists.org/bugtraq/2019/Jun/8 | Mailing List |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/153223/Moxa-AWK-3121-1.14-Information-Disclosure-Command-Execution.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Awk-3121 Firmware Search vendor "Moxa" for product "Awk-3121 Firmware" | 1.14 Search vendor "Moxa" for product "Awk-3121 Firmware" and version "1.14" | - |
Affected
| in | Moxa Search vendor "Moxa" | Awk-3121 Search vendor "Moxa" for product "Awk-3121" | - | - |
Safe
|