MOXA EDR-G903 Unauthorized Access Vulnerability and Insufficient Entropy Weakness
BID:57897
Info
MOXA EDR-G903 Unauthorized Access Vulnerability and Insufficient Entropy Weakness
| Bugtraq ID: | 57897 |
| Class: | Design Error |
| CVE: |
CVE-2012-4694 CVE-2012-4712 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2013 12:00AM |
| Updated: | Feb 11 2013 12:00AM |
| Credit: | Neil Smith |
| Vulnerable: |
Moxa EDR-G903 2.1 |
| Not Vulnerable: |
Moxa EDR-G903 2.11 |
Discussion
MOXA EDR-G903 Unauthorized Access Vulnerability and Insufficient Entropy Weakness
MOXA EDR-G903 is prone to an unauthorized access vulnerability and a weakness in the entropy of the generated key.
Successful exploits will allow attackers to gain access to the device and sensitive information. Successful exploits may result in the attacker executing arbitrary commands or gain unauthorized access on the affected system.
MOXA EDR-G903 is prone to an unauthorized access vulnerability and a weakness in the entropy of the generated key.
Successful exploits will allow attackers to gain access to the device and sensitive information. Successful exploits may result in the attacker executing arbitrary commands or gain unauthorized access on the affected system.
Exploit / POC
MOXA EDR-G903 Unauthorized Access Vulnerability and Insufficient Entropy Weakness
An attacker can leverage this issue using readily available network utilities.
An attacker can leverage this issue using readily available network utilities.
Solution / Fix
MOXA EDR-G903 Unauthorized Access Vulnerability and Insufficient Entropy Weakness
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.