CVE-2017-12123
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
14/05/2018
Last modified:
09/12/2022
Description
An exploitable clear text transmission of password vulnerability exists in the web server and telnet functionality of Moxa EDR-810 V4.1 build 17030317. An attacker can look at network traffic to get the admin password for the device. The attacker can then use the credentials to login as admin.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:moxa:edr-810_firmware:4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:h:moxa:edr-810:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



