CVE-2016-8346
published 2017-02-13CVE-2016-8346: An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is…
PriorityP343high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.08%
79.3th percentile
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | edr-810_firmware | <= 3.12 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa EDR-810 Industrial Secure Router Privilege Escalation Vulnerability
cisa_ics·2019-10-23
Moxa EDR-810 Industrial Secure Router Privilege Escalation Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa EDR-810 Industrial Secure Router Privilege Escalation Vulnerability
Last RevisedOctober 23, 2019
Alert CodeICSA-16-294-01
## OVERVIEW
Independent researcher Maxim Rupp has identified a privilege escalation vulnerability in Moxa’s EDR-810 Industrial Secure Router. Moxa has produced firmware to mitigate this vulnerability.
This vulnerability could be exploited remotely.
## AFFECTED PRODUCTS
The following EDR-810 versions are affected:
- EDR-810 using firmware versions prior to V3.13
## IMPACT
Successful exploitation of this vulnerability may allow a remote attacker to e
GHSA
GHSA-2hg5-44f2-x8xw: An issue was discovered in Moxa EDR-810 Industrial Secure Router
ghsa_unreviewed·2022-05-17
CVE-2016-8346 [HIGH] CWE-532 GHSA-2hg5-44f2-x8xw: An issue was discovered in Moxa EDR-810 Industrial Secure Router
An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access configuration and log files (PRIVILEGE ESCALATION).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published