CVE-2017-13701: Infoleak
An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13701?
CVE-2017-13701 is considered to have a high severity due to the insecure storage of sensitive information including passwords.
How do I fix CVE-2017-13701?
To fix CVE-2017-13701, ensure that all sensitive information, especially passwords, are stored securely with proper hashing and encryption methods.
What devices are affected by CVE-2017-13701?
CVE-2017-13701 affects MOXA EDS-G512E devices running firmware version 5.1.
What type of sensitive information is exposed in CVE-2017-13701?
CVE-2017-13701 exposes passwords stored without encryption, which can be accessed from backup files.
Is there a patch available for CVE-2017-13701?
As of the last update, a specific patch for CVE-2017-13701 has not been publicly disclosed, so users should contact MOXA for further assistance.