QID 591206
Date Published: 2022-11-24
QID 591206: Moxa EDR-810 Web Server strcmp Multiple Denial of Service (DoS) Multiple Vulnerabilities (TALOS-2017-0474)
AFFECTED PRODUCTS
Moxa EDR-810 V4.1 build 17030317
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA_LOG.ini, /MOXA_CFG.ini, or /MOXA_CFG2.ini" without a cookie header to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2017-0474 for affected packages and patching details.
Vendor References
- TALOS-2017-0474 -
www.talosintelligence.com/vulnerability_reports/TALOS-2017-0474
CVEs related to QID 591206
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| TALOS-2017-0474 |
|