Mxview
Vendor:
First CVE: Apr 14, 2017 · Active for 9 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mxview over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2017
9 years ago
Most Recent CVE
Apr 14, 2022
1,562 days ago
CVE Severity & Scoring
Mxview13 CVEs
62%
38%
All CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local3 (23.1%)
Network10 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (23.1%)
High0 (0.0%)
None10 (76.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7456HIGH Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials. | Apr 14, 2017 | 7.5 | 52 | NO | YES |
CVE-2017-7455HIGH Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control. | Apr 14, 2017 | 7.5 | 44 | NO | YES |
CVE-2021-38454CRITICAL A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code | Oct 12, 2021 | 10.0 | 38 | NO | NO |
CVE-2021-40390CRITICAL An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An | Apr 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-38458CRITICAL A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code | Oct 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-38456CRITICAL A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default | Oct 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-38452CRITICAL A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code | Oct 12, 2021 | 9.1 | 28 | NO | NO |
CVE-2021-38460HIGH A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code | Oct 12, 2021 | 7.5 | 24 | NO | NO |
CVE-2020-13537HIGH An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker c | Nov 5, 2020 | 7.8 | 24 | NO | NO |
CVE-2018-7506HIGH The private key of the web server in Moxa MXview versions 2.8 and prior is able to be read and accessed via an HTTP GET request, which may allow a remote attacker to decrypt encryp | Apr 6, 2018 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
15.4% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Mxview
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.4 | 2 | 8.7 | 1.5% | 0 | 0 |
| 3.1.8 | 2 | 7.8 | 0.5% | 0 | 0 |
| 2.8 | 2 | 7.5 | 22.8% | 0 | 2 |