CVE-2018-10698
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an attacker can easily connect to the TELNET daemon using the default credentials if they have not been changed by the user.
Se encontró un problema en los dispositivos Moxa AWK-3121 versión 1.14. El dispositivo habilita un servicio TELNET sin cifrar de forma predeterminada. Esto permite que un atacante que haya podido obtener una posición MITM pueda detectar fácilmente el tráfico entre el dispositivo y el usuario. Además, un atacante puede conectarse fácilmente al dominio TELNET utilizando las credenciales predeterminadas si el usuario no las ha modificado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-03 CVE Reserved
- 2019-06-07 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-311: Missing Encryption of Sensitive Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/samuelhuntley/Moxa_AWK_1121/blob/master/Moxa_AWK_1121 | Third Party Advisory | |
https://seclists.org/bugtraq/2019/Jun/8 | Mailing List |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/153223/Moxa-AWK-3121-1.14-Information-Disclosure-Command-Execution.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Awk-3121 Firmware Search vendor "Moxa" for product "Awk-3121 Firmware" | 1.14 Search vendor "Moxa" for product "Awk-3121 Firmware" and version "1.14" | - |
Affected
| in | Moxa Search vendor "Moxa" | Awk-3121 Search vendor "Moxa" for product "Awk-3121" | - | - |
Safe
|