{
    "id": "CVE-2021-38454",
    "published": "2021-10-12 14:15:08",
    "last_modified": "2026-06-17 04:02:07",
    "cvss_score": "10.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-284",
    "description": "A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.",
    "epss_score": "0.15789",
    "epss_percentile": "0.96781",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-03 18:17:30",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "EPSS 15.8% — above the 10% action threshold."
    },
    "products": [
        {
            "vendor": "moxa",
            "product": "mxview"
        }
    ],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://us-cert.cisa.gov/ics/advisories/icsa-21-278-03",
        "https://us-cert.cisa.gov/ics/advisories/icsa-21-278-03"
    ]
}