CVE-2017-12123

HIGH

Moxa EDR-810 <V4.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0475

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-522
Status published
Products (1)
moxa/edr-810_firmware 4.1
Published May 14, 2018
Tracked Since Feb 18, 2026