CVE-2017-12129 LOW

CVE-2017-12129

Vendor Talos
Product Moxa
Published May 14, 2018
Last update September 17, 2024

CVSS base score

3.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

An exploitable Weak Cryptography for Passwords vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. An attacker could intercept weakly encrypted passwords and could brute force them.

Key dates

02Disclosure timeline

May 14, 2018 CVE published
September 17, 2024 Record updated