CVE-2017-12127: Medium severity moxa edr-810 vpn 2g-sfp firmware vulnerability
Published May 14, 2018
·Updated
A password storage vulnerability exists in the operating system functionality of Moxa EDR-810 V4.1 build 17030317. An attacker with shell access could extract passwords in clear text from the device.
Affected Software
2 affected components
MOXA Edr-810 Firmware=4.1
MOXA EDR-810
Event History
May 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12127?
CVE-2017-12127 has a medium severity rating due to the potential for attackers to extract sensitive passwords.
2
How do I fix CVE-2017-12127?
To mitigate CVE-2017-12127, update the Moxa EDR-810 firmware to a secure version that addresses this vulnerability.
3
Who is affected by CVE-2017-12127?
CVE-2017-12127 affects users of Moxa EDR-810 running firmware version 4.1 build 17030317.
4
What type of access does an attacker need for CVE-2017-12127?
An attacker requires shell access to the Moxa EDR-810 device to exploit CVE-2017-12127.
5
What are the consequences of CVE-2017-12127 exploitation?
Exploitation of CVE-2017-12127 can lead to unauthorized disclosure of sensitive passwords stored in clear text.