CVE-2017-13701: Infoleak

Published Nov 23, 2017
·
Updated

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.

Affected Software

2 affected components
MOXA Eds-g512e Firmware=5.1
MOXA EDS-G512E

Event History

Nov 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-13701?

CVE-2017-13701 is considered to have a high severity due to the insecure storage of sensitive information including passwords.

2

How do I fix CVE-2017-13701?

To fix CVE-2017-13701, ensure that all sensitive information, especially passwords, are stored securely with proper hashing and encryption methods.

3

What devices are affected by CVE-2017-13701?

CVE-2017-13701 affects MOXA EDS-G512E devices running firmware version 5.1.

4

What type of sensitive information is exposed in CVE-2017-13701?

CVE-2017-13701 exposes passwords stored without encryption, which can be accessed from backup files.

5

Is there a patch available for CVE-2017-13701?

As of the last update, a specific patch for CVE-2017-13701 has not been publicly disclosed, so users should contact MOXA for further assistance.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203