Vulnerability Description
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Eds-G512E Firmware | 5.1 |
| Moxa | Eds-G512E | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101966Third Party AdvisoryVDB Entry
- https://www.sentryo.net/wp-content/uploads/2017/11/Switch-Moxa-Analysis.pdfMitigationThird Party Advisory
- http://www.securityfocus.com/bid/101966Third Party AdvisoryVDB Entry
- https://www.sentryo.net/wp-content/uploads/2017/11/Switch-Moxa-Analysis.pdfMitigationThird Party Advisory
FAQ
What is CVE-2017-13701?
CVE-2017-13701 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stor...
How severe is CVE-2017-13701?
CVE-2017-13701 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-13701?
Check the references section above for vendor advisories and patch information. Affected products include: Moxa Eds-G512E Firmware, Moxa Eds-G512E.