Denial of service in Moxa products - CVE-2017-16719

 

Denial of service in Moxa products - CVE-2017-16719

Published: November 21, 2017 / Updated: November 21, 2017


Vulnerability identifier: #VU9374
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16719
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to improper neutralization of special elements in output used by a downstream component. A remote attacker can inject specially crafted packets that and disrupt the availability of the device.

Successful exploitation of the vulnerability results in denial of service.


Affected software

NPort 5150
NPort 5110
NPort 5130

How to mitigate CVE-2017-16719

Install update from vendor's website.


External References

Related Security Bulletins