First published: Wed Aug 24 2016(Updated: )
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Oncell G3001 Firmware | <=1.6 | |
Moxa Oncell G3111 | ||
Moxa Oncell G3151 | ||
Moxa Oncell G3211 | ||
Moxa Oncell G3251 | ||
Moxa Oncell G3100v2 Firmware | <=2.7 | |
Moxa OnCell G3100V2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5812 is classified as a medium severity vulnerability due to improper password storage.
To fix CVE-2016-5812, upgrade the Moxa OnCell G3100V2 firmware to version 2.8 or above, or G3001 firmware to version 1.7 or above.
CVE-2016-5812 affects Moxa OnCell G3100V2 devices before firmware version 2.8 and OnCell G3001 devices before firmware version 1.7.
CVE-2016-5812 is a vulnerability related to cleartext password storage, making sensitive information accessible.
Yes, local users can exploit CVE-2016-5812 to obtain sensitive information by accessing a configuration file.