1.9
CVSSv2

CVE-2017-7457

Published: 14/04/2017 Updated: 16/08/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5 | Impact Score: 3.6 | Exploitability Score: 1.3
VMScore: 195
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

Vulnerable Product Search on Vulmon Subscribe to Product

moxa mx-aopc server 1.5

Exploits

[+] Credits: John Page AKA HYP3RLINX [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/MOXA-MX-AOPC-SERVER-v15-XML-EXTERNAL-ENTITYtxt [+] ISR: ApparitionSec Vendor: ============ wwwmoxacom Product: ======================= MX-AOPC UA SERVER - 15 Moxa's MX-AOPC UA Suite is the firs ...
Moxa MX-AOPC UA server version 15 suffers from an XML external entity injection vulnerability ...