VYPR

Eds G512e Firmware

Sign in to watch

by Moxa

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-13701Cri0.649.80.00Nov 23, 2017An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no salt for password hashing. Indeed passwords are stored without being ciphered with a timestamped ciphering method.
CVE-2017-13699Hig0.497.50.00Nov 23, 2017An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall value that is sent in cleartext as a POST parameter. An attacker could reverse the password encryption algorithm to retrieve it.
CVE-2017-13703Hig0.497.50.00Nov 17, 2017An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.