CVE-2016-0879

HIGH

Moxa Secure Router EDR-G903 <3.4.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-042-01

Scores

CVSS v3 7.5
EPSS 0.0060
EPSS Percentile 69.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532
Status published
Products (1)
moxa/edr-g903_firmware < 3.4.12
Published May 31, 2016
Tracked Since Feb 18, 2026