CVE-2017-12129: Weak Encryption
Published May 14, 2018
·Updated
An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.
Affected Software
2 affected components
MOXA Edr-810 Firmware=4.1
MOXA EDR-810
Event History
May 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-12129?
CVE-2017-12129 has a medium severity rating due to the potential for interception and brute-forcing of weakly encrypted passwords.
2
How do I fix CVE-2017-12129?
To fix CVE-2017-12129, update the Moxa EDR-810 firmware to a version that addresses the weak cryptography issue.
3
Who is affected by CVE-2017-12129?
CVE-2017-12129 affects Moxa EDR-810 devices running firmware version 4.1 build 17030317.
4
What type of vulnerability is CVE-2017-12129?
CVE-2017-12129 is classified as a Weak Cryptography for Passwords vulnerability.
5
Can CVE-2017-12129 lead to unauthorized access?
Yes, CVE-2017-12129 can lead to unauthorized access if attackers successfully brute force weakly encrypted passwords.