First published: Thu Nov 16 2017(Updated: )
An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exploit a flaw in the handling of Ethernet frame padding that may allow for information exposure.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport 5110 Firmware | =2.2 | |
Moxa Nport 5110 Firmware | =2.4 | |
Moxa Nport 5110 Firmware | =2.6 | |
Moxa Nport 5110 Firmware | =2.7 | |
Moxa NPort 5110 | ||
Moxa Nport 5130 Firmware | <=3.7 | |
Moxa Nport 5130 | ||
Moxa Nport 5150 Firmware | <=3.7 | |
Moxa Nport 5150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-16715 is high with a CVSS score of 7.5.
The affected software for CVE-2017-16715 is Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7, and NPort 5150 Version 3.7 and prior.
The vulnerability type of CVE-2017-16715 is Information Exposure.
An attacker may be able to exploit CVE-2017-16715 by exploiting a flaw in the handling of Ethernet frame padding.
Yes, you can find references for CVE-2017-16715 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/101885), [ICSA-17-320-01](https://ics-cert.us-cert.gov/advisories/ICSA-17-320-01).