Information Disclosure and Man-in-the-Middle Vulnerability in Moxa AWK-3121 Devices
CVE-2018-10694
8.1HIGH
Summary
The Moxa AWK-3121 1.14 devices have a significant security issue due to their use of an open Wi-Fi connection without any encryption by default. This configuration allows an attacker to intercept unencrypted traffic between the user's computer and the device. As a result, sensitive data such as credentials transmitted over HTTP and TELNET can be easily captured. Additionally, the lack of proper security can enable an attacker to perform Man-in-the-Middle (MITM) attacks, leading to further exploitation, including the potential to inject malicious content onto the user's machine.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved