CVE-2016-0879
Published May 31, 2016
Last updated 3 years ago
Overview
- Description
- Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which allows remote attackers to obtain sensitive information by requesting these files at an unspecified URL.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-532
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:moxa:edr-g903_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "78F17387-5413-4188-9336-92559EA65E61", "versionEndExcluding": "3.4.12" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:moxa:edr-g903:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FDB89B47-4598-4F6D-951F-DF546C8CAA96" } ], "operator": "OR" } ], "operator": "AND" } ]