PT-2017-3792 · Moxa · Moxa Eds-G516E Series+1

Published

2017-05-09

·

Updated

2020-03-26

·

CVE-2020-6979

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa EDS-G516E Series versions 5.2 or lower Moxa EDS-510E (affected versions not specified)
Description The issue is related to the use of a hard-coded cryptographic key in the configuration file of the affected products. This increases the possibility that confidential data can be recovered. An attacker, acting remotely, could exploit this issue to gain unauthorized access to protected information.
Recommendations For Moxa EDS-G516E Series versions 5.2 or lower, consider updating to a version higher than 5.2 to mitigate the risk. For Moxa EDS-510E, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the configuration file to minimize the risk of exploitation.

Using Hardcoded Credentials

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03255
CVE-2020-6979

Affected Products

Moxa Eds-510E
Moxa Eds-G516E Series