CVE-2017-7913: Critical severity moxa oncell g3110-hsdpa firmware vulnerability
A Plaintext Storage of a Password issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application's configuration file contains parameters that represent passwords in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7913?
CVE-2017-7913 is classified as a medium severity vulnerability due to the risk associated with plaintext storage of passwords.
How do I fix CVE-2017-7913?
To mitigate CVE-2017-7913, upgrade the affected Moxa OnCell devices to firmware versions that do not store passwords in plaintext.
Which Moxa OnCell devices are affected by CVE-2017-7913?
CVE-2017-7913 affects Moxa OnCell G3110-HSPA, G3110-HSDPA, G3150-HSDPA, and 5104-HSDPA devices running specified older firmware versions.
What is the consequence of CVE-2017-7913 vulnerability?
The consequence of CVE-2017-7913 is that attackers can easily access user credentials stored in plaintext, potentially leading to unauthorized access.
Is there a patch available for CVE-2017-7913?
Yes, patches are available in newer firmware releases for the affected Moxa OnCell devices to resolve CVE-2017-7913.