CVE-2017-12123

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:edr-810_firmware:4.1:*:*:*:*:*:*:*
cpe:2.3:h:moxa:edr-810:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:08

Type Values Removed Values Added
References () https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0475 - Exploit, Third Party Advisory () https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0475 - Exploit, Third Party Advisory

Information

Published : 2018-05-14 20:29

Updated : 2024-11-21 03:08


NVD link : CVE-2017-12123

Mitre link : CVE-2017-12123

CVE.ORG link : CVE-2017-12123


JSON object : View

Products Affected

moxa

  • edr-810_firmware
  • edr-810
CWE
CWE-522

Insufficiently Protected Credentials