CVE-2016-8717
published 2018-04-02CVE-2016-8717: An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.33%
81.5th percentile
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | awk-3131a_firmware | — | — |
| talos | moxa | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Snort Rule SID 40758
- →Monitor SSH and Telnet login attempts using the hard-coded username '94jo3dkru4' against Moxa AWK-3131A devices; any successful or attempted authentication with this credential is a strong indicator of exploitation. ↗
- →Deploy Snort rule SID 40758 to detect exploitation attempts of this hard-coded credential vulnerability on network traffic. ↗
- ·The hard-coded root account cannot be disabled or removed through normal device management; patching to the fixed firmware is the only permanent remediation. ↗
- ·If patching is not immediately possible, disable remotely-accessible services (SSH and Telnet) to reduce attack surface. ↗
- ·Snort rules for this vulnerability are subject to change as new information emerges; review Defense Centers or Snort.org for the latest rule versions. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Hard-coded Credential Flaw in Moxa ICS Wireless Access Points Identified and Fixed
blogs_talos·2017-04-21·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Hard-coded Credential Flaw in Moxa ICS Wireless Access Points Identified and Fixed
## Vulnerability Spotlight: Hard-coded Credential Flaw in Moxa ICS Wireless Access Points Identified and Fixed
Earlier this month, Talos responsibly disclosed a set of vulnerabilities in Moxa ICS wireless access points. While most of the vulnerabilities were addressed in the previous set of advisories, Talos has continued to work with Moxa to ensure all remaining vulnerabilities that Talos identified are patched. Today in coordination with Moxa, Talos is disclosing the TALOS-2016-0231, a hard-coded credential vulnerability that could allow an attacker to gain complete control of the device. Moxa has released a software update to address TALOS-2016-0231 and other bugs.
## Vulnerability Details This vulnerability was identified by Patrick DeSantis of Talos.
TALOS-2016-0231 (CVE-2016-8717)
Talos
Vulnerability Spotlight: Hard-coded Credential Flaw in Moxa ICS Wireless Access Points Identified and Fixed
blogs_talos·2017-04-21·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Hard-coded Credential Flaw in Moxa ICS Wireless Access Points Identified and Fixed
Earlier this month, Talos responsibly disclosed a set of vulnerabilities in Moxa ICS wireless access points. While most of the vulnerabilities were addressed in the previous set of advisories, Talos has continued to work with Moxa to ensure all remaining vulnerabilities that Talos identified are patched. Today in coordination with Moxa, Talos is disclosing the TALOS-2016-0231, a hard-coded credential vulnerability that could allow an attacker to gain complete control of the device. Moxa has released a software update to address TALOS-2016-0231 and other bugs.
## Vulnerability Details This vulnerability was identified by Patrick DeSantis of Talos.
TALOS-2016-0231 (CVE-2016-8717) is a hard-coded credential vulnerability within Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP
2018-04-02
Published