PT-2017-3792 · Moxa · Moxa Eds-G516E Series+1
Published
2017-05-09
·
Updated
2020-03-26
·
CVE-2020-6979
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa EDS-G516E Series versions 5.2 or lower
Moxa EDS-510E (affected versions not specified)
Description
The issue is related to the use of a hard-coded cryptographic key in the configuration file of the affected products. This increases the possibility that confidential data can be recovered. An attacker, acting remotely, could exploit this issue to gain unauthorized access to protected information.
Recommendations
For Moxa EDS-G516E Series versions 5.2 or lower, consider updating to a version higher than 5.2 to mitigate the risk.
For Moxa EDS-510E, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting access to the configuration file to minimize the risk of exploitation.
Using Hardcoded Credentials
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Eds-510E
Moxa Eds-G516E Series