The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encrypted information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103722 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-095-02 | third party advisory us government resource |