Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-16-042-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2016-05-30 18:59
Updated : 2022-04-12 11:05
NVD link : CVE-2016-0879
Mitre link : CVE-2016-0879
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
moxa
- edr-g903
- edr-g903_firmware