Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2017/Apr/49 | mailing list exploit third party advisory |
http://hyp3rlinx.altervista.org/advisories/MOXA-MXVIEW-v2.8-REMOTE-PRIVATE-KEY-DISCLOSURE.txt | third party advisory exploit |
https://www.exploit-db.com/exploits/41850/ | exploit |
http://packetstormsecurity.com/files/142074/Moxa-MXview-2.8-Private-Key-Disclosure.html | exploit vdb entry third party advisory |