CVE-2016-8346: High severity MOXA Edr-810 Firmware vulnerability
Published Feb 13, 2017
·Updated
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).
Affected Software
6 affected components
MOXA Edr-810 Firmware<=3.12
MOXA EDR-810
MOXA Edr-810-vpn
All of the following
MOXA Edr-810 Firmware<=3.12
Any of the following
MOXA EDR-810
MOXA Edr-810-vpn
Event History
Feb 13, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Data Sourced
via NVD·09:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8346?
CVE-2016-8346 is classified as a privilege escalation vulnerability.
2
How do I fix CVE-2016-8346?
To fix CVE-2016-8346, update the Moxa EDR-810 firmware to version 3.13 or later.
3
What types of devices are affected by CVE-2016-8346?
CVE-2016-8346 affects Moxa EDR-810 Industrial Secure Routers running firmware version 3.12 or earlier.
4
What can a malicious user do with CVE-2016-8346?
A malicious user can access sensitive configuration and log files through a specific URL on the web server.
5
Is there a workaround for CVE-2016-8346 if I can't update immediately?
There are no specific workarounds documented for CVE-2016-8346, so it is recommended to apply the firmware update.