QID 591017
Date Published: 2022-08-26
QID 591017: Moxa EDR-810 Web Rivest Shamir Adleman (RSA) Key Generation Command Injection Vulnerability (TALOS-2017-0473)
AFFECTED PRODUCTS
Moxa EDR-810 V4.1 build 17030317
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the rsakey_name= parm in the "/goform/WebRSAKEYGen" uri to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2017-0473 for affected packages and patching details.
Vendor References
- TALOS-2017-0473 -
talosintelligence.com/vulnerability_reports/TALOS-2017-0473
CVEs related to QID 591017
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TALOS-2017-0473 |
|