CVE-2016-0876
published 2016-05-31CVE-2016-0876: Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.14%
62.8th percentile
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | edr-g903_firmware | < 3.4.12 | 3.4.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mf9w-62p6-2jh9: Moxa Secure Router EDR-G903 devices before 3
ghsa_unreviewed·2022-05-13
CVE-2016-0876 [HIGH] CWE-312 GHSA-mf9w-62p6-2jh9: Moxa Secure Router EDR-G903 devices before 3
Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to discover cleartext passwords by reading a configuration file.
Red Hat
expat: Little entropy used for hash initialization
vendor_redhat·2016-06-04·CVSS 4.3
CVE-2016-5300 [MEDIUM] CWE-331 expat: Little entropy used for hash initialization
expat: Little entropy used for hash initialization
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0876.
Package: expat (Red Hat Directory Server 8) - Under investigation
Package: expat (Red Hat Enterprise Linux 5) - Will not fix
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Not affected
Package: xmlrpc-c (Red Hat Enterprise Linux 5) - Will not fix
Package: xulrunner (Red Hat Enterprise Linux 5) - Not affected
Package: compat-expat1 (Red Hat Enterprise Linux 6) - Not affected
Pack
CISA ICS
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
cisa_ics·2016-05-17
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
Last RevisedOctober 23, 2019
Alert CodeICSA-16-042-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-16-042-01 Moxa EDR‑G903 Secure Router Vulnerabilities that was published May 17, 2016, on the NCCIC/ICS-CERT web site.
Independent researcher Maxim Rupp has identified vulnerabilities in Moxa’s EDR‑G903 secure routers. Moxa has produced a new firmware version to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following Moxa
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8629 keycloak: user deletion via incorrect permissions check
bugzilla·2016-10-26·CVSS 6.5
CVE-2016-8629 [MEDIUM] CVE-2016-8629 keycloak: user deletion via incorrect permissions check
CVE-2016-8629 keycloak: user deletion via incorrect permissions check
https://issues.jboss.org/browse/KEYCLOAK-3667
Discussion:
This issue has been addressed in the following products:
Via RHSA-2017:0876 https://access.redhat.com/errata/RHSA-2017:0876
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.1 for RHEL 7
Via RHSA-2017:0873 https://access.redhat.com/errata/RHSA-2017:0873
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.1 for RHEL 6
Via RHSA-2017:0872 https://access.redhat.com/errata/RHSA-2017:0872
Bugzilla
CVE-2016-5300 expat: Little entropy used for hash initialization
bugzilla·2016-06-06·CVSS 4.3
CVE-2016-5300 [MEDIUM] CVE-2016-5300 expat: Little entropy used for hash initialization
CVE-2016-5300 expat: Little entropy used for hash initialization
It was found that original fix for CVE-2012-0876 used too little entropy for the hash intilization.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/473
Discussion:
Created compat-expat1 tracking bugs for this issue:
Affects: fedora-all [bug 1343087]
---
Created expat tracking bugs for this issue:
Affects: fedora-all [bug 1343086]
---
Created mingw-expat tracking bugs for this issue:
Affects: fedora-all [bug 1343088]
Affects: epel-7 [bug 1343090]
---
Created expat21 tracking bugs for this issue:
Affects: epel-all [bug 1343089]
---
Created attachment 1165210
Proposed upstream patch
2016-05-31
Published