Moxa Eds-G512E Firmware vulnerabilities

7 known vulnerabilities affecting moxa/eds-g512e_firmware.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2019-19707HIGHCVSS 7.5≤ 6.02019-12-11
CVE-2019-19707 [HIGH] CVE-2019-19707: On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service c On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINET DCE-RPC endpoint discovery packets.
nvd
CVE-2017-13701CRITICALCVSS 9.8v5.12017-11-23
CVE-2017-13701 [CRITICAL] CWE-200 CVE-2017-13701: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensi An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.
nvd
CVE-2017-13699HIGHCVSS 7.5v5.12017-11-23
CVE-2017-13699 [HIGH] CWE-326 CVE-2017-13699: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reverse the password encryption algorithm to retrieve it.
nvd
CVE-2017-13698HIGHCVSS 7.5v5.12017-11-23
CVE-2017-13698 [HIGH] CVE-2017-13698: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract publ An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. An attacker could extract public and private keys from the firmware image available on the MOXA website and could use them against a production switch that has the default keys embedded.
nvd
CVE-2017-13703HIGHCVSS 7.5v5.12017-11-17
CVE-2017-13703 [HIGH] CWE-20 CVE-2017-13703: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur. An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.
nvd
CVE-2017-13700MEDIUMCVSS 4.8v5.12017-11-17
CVE-2017-13700 [MEDIUM] CWE-79 CVE-2017-13700: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administra An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.
nvd
CVE-2017-13702MEDIUMCVSS 5.3v5.12017-11-17
CVE-2017-13702 [MEDIUM] CWE-200 CVE-2017-13702: An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipul An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.
nvd