Information Disclosure and Man-in-the-Middle Vulnerability in Moxa AWK-3121 Devices
CVE-2018-10694

8.1HIGH

Key Information:

Vendor
Moxa
Vendor
CVE Published:
7 June 2019

Summary

The Moxa AWK-3121 1.14 devices have a significant security issue due to their use of an open Wi-Fi connection without any encryption by default. This configuration allows an attacker to intercept unencrypted traffic between the user's computer and the device. As a result, sensitive data such as credentials transmitted over HTTP and TELNET can be easily captured. Additionally, the lack of proper security can enable an attacker to perform Man-in-the-Middle (MITM) attacks, leading to further exploitation, including the potential to inject malicious content onto the user's machine.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.