First published: Tue May 31 2016(Updated: )
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Edr-g903 Firmware | <3.4.12 | |
Moxa EDR-G903 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0879 is classified as a high-severity vulnerability due to the potential for remote attackers to access sensitive information.
To fix CVE-2016-0879, upgrade the Moxa EDR-G903 devices to firmware version 3.4.12 or later.
CVE-2016-0879 affects Moxa Secure Router EDR-G903 devices running firmware versions prior to 3.4.12.
CVE-2016-0879 can lead to the exposure of sensitive configuration and log files.
There is no official workaround for CVE-2016-0879; therefore, updating to the latest firmware is the recommended approach.