PT-2015-3452 · Moxa · Moxa Eds-408A+1

Published

2015-09-03

·

Updated

2015-09-14

·

CVE-2015-6466

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Moxa EDS-405A and Moxa EDS-408A versions prior to 3.6
Description The issue is related to insufficient protection of the web page structure in the Diagnosis Ping feature of the administrative web interface. This can be exploited by a remote attacker to execute arbitrary code. The vulnerability also allows for cross-site scripting (XSS) attacks, where an attacker can inject arbitrary web script or HTML.
Recommendations For versions prior to 3.6, update the firmware to version 3.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the Diagnosis Ping feature in the administrative web interface until a patch is available. Avoid using unspecified fields in the Diagnosis Ping feature that may be vulnerable to XSS attacks until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05172
CVE-2015-6466

Affected Products

Moxa Eds-405A
Moxa Eds-408A