CVE-2017-12124: Null Pointer Dereference
Published May 14, 2018
·Updated
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in the web server crashing. An attacker can send a crafted URI to trigger this vulnerability.
Affected Software
2 affected components
MOXA Edr-810 Firmware=4.1
MOXA EDR-810
Event History
May 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12124?
CVE-2017-12124 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-12124?
To fix CVE-2017-12124, update the Moxa EDR-810 firmware to a version that addresses this vulnerability.
3
What software versions are affected by CVE-2017-12124?
CVE-2017-12124 affects Moxa EDR-810 firmware version 4.1 build 17030317.
4
What are the consequences of exploiting CVE-2017-12124?
Exploiting CVE-2017-12124 can lead to the web server crashing, resulting in a denial of service.
5
Is CVE-2017-12124 exploitable remotely?
Yes, an attacker can exploit CVE-2017-12124 remotely by sending a specially crafted HTTP URI.