As of June 15, 2022, this site no longer supports Internet Explorer. Please use another browser for the best experience on our site.

Product support

Security Advisories

SUMMARY

MXview Series Network Management Software Vulnerabilities

  • Security Advisory ID: MPSA-220201
  • Version: V1.2
  • Release Date: Mar 17, 2022
  • Reference:
    • TALOS-2021-1401, TALOS-2021-1403
    • CVE-2021-40390, CVE-2021-40392

Multiple product vulnerabilities were identified in Moxa’s MXview Series Network Management Software. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Use of Hard-coded Credentials
(CWE-798)
CVE-2021-40390
An attacker can send a specially-crafted HTTP request and gain unauthorized access.
2 Cleartext Transmission of Sensitive Information (CWE-319)
CVE-2021-40392
An attacker can sniff network traffic to exploit sensitive information.

 

AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
MXview Series

CVE-2021-40390:  Software Version 3.2.0 to 3.2.4. 

CVE-2021-40392:  Software Version 3.2.4 or lower. 

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
MXview Series

For item 1: Please upgrade to software version 3.2.6 or higher. (Download Link)

For item 2: Users can manually check the "Disable HTTP Port" feature when installing or starting the MXview Server to mitigate this risk.

Please follow the steps below to upgrade your version of MXview:

  1. Back up the current MXview database.
  2. Stop the MXview Service.
  3. Download the latest version of MXview.
  4. Run the installer with the latest version of MXview.

Acknowledgment:

We would like to express our appreciation to Patrick DeSantis of Cisco Talos for reporting the vulnerability, working with us to help enhance the security of our products, and helping us provide a better service to our customers.
 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Feb 11, 2022
1.1 Added Upgrade Process Feb 14, 2022
1.2 CVE-2021-40390 Affected Versions 3.2.4 or lower changed to 3.2.0 to 3.2.4 Mar 17, 2022

Relevant Products

MXview Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag
You have some items waiting in your bag; click here to finish your quote!
Feedback