QID 590989
Date Published: 2022-08-24
QID 590989: Moxa EDR-810 Web Server ping Command Injection Vulnerability (TALOS-2017-0472)
AFFECTED PRODUCTS
Moxa EDR-810 V4.1 build 17030317
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the /goform/net_WebPingGetValue URI to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2017-0472 for affected packages and patching details.
Vendor References
- TALOS-2017-0472 -
talosintelligence.com/vulnerability_reports/TALOS-2017-0472
CVEs related to QID 590989
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TALOS-2017-0472 |
|