VulnerabilityModified
CVE-2017-14030
The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
HIGH 7.8EPSS 0.37%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.37%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Moxa MXview v2.8 and prior. The unquoted service path escalation vulnerability could allow an authorized user with file access to escalate privileges by inserting arbitrary code into the unquoted service path.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.37% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-428
- Affected
- moxa/mxview
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/102494Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102494Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-011-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.