QID 591014
Date Published: 2022-08-26
QID 591014: Moxa EDR-810 Web Server Certificate Signing Request Command Injection Vulnerability (TALOS-2017-0477)
AFFECTED PRODUCTS
Moxa EDR-810 V4.1 build 17030317
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2017-0477 for affected packages and patching details.
Vendor References
- TALOS-2017-0477 -
talosintelligence.com/vulnerability_reports/TALOS-2017-0477
CVEs related to QID 591014
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TALOS-2017-0477 |
|