CVE-2016-0879
published 2016-05-31CVE-2016-0879: Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.22%
80.6th percentile
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | edr-g903_firmware | < 3.4.12 | 3.4.12 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
cisa_ics·2016-05-17
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa EDR-G903 Secure Router Vulnerabilities (Update A)
Last RevisedOctober 23, 2019
Alert CodeICSA-16-042-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-16-042-01 Moxa EDR‑G903 Secure Router Vulnerabilities that was published May 17, 2016, on the NCCIC/ICS-CERT web site.
Independent researcher Maxim Rupp has identified vulnerabilities in Moxa’s EDR‑G903 secure routers. Moxa has produced a new firmware version to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following Moxa
GHSA
GHSA-4mj8-j4rr-9758: Moxa Secure Router EDR-G903 devices before 3
ghsa_unreviewed·2022-05-13
CVE-2016-0879 [HIGH] CWE-532 GHSA-4mj8-j4rr-9758: Moxa Secure Router EDR-G903 devices before 3
Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-05-31
Published