Learn about CVE-2017-14436, a high-severity denial of service vulnerability in Moxa EDR-810 V4.1 build 17030317. Find out the impact, affected systems, exploitation details, and mitigation steps.
CVE-2017-14436, published on April 13, 2018, addresses a denial of service vulnerability in Moxa EDR-810 V4.1 build 17030317.
Understanding CVE-2017-14436
This CVE entry describes a specific vulnerability in the web server function of Moxa EDR-810 V4.1 build 17030317 that can be exploited for denial of service attacks.
What is CVE-2017-14436?
The vulnerability in Moxa EDR-810 V4.1 build 17030317 allows attackers to trigger a null pointer dereference by sending a specially crafted HTTP URI, leading to a denial of service.
The Impact of CVE-2017-14436
The impact of this vulnerability is rated as HIGH with a CVSS base score of 7.5. It can result in a denial of service attack on the affected system.
Technical Details of CVE-2017-14436
This section provides more technical insights into the vulnerability.
Vulnerability Description
The vulnerability in the web server function of Moxa EDR-810 V4.1 build 17030317 can be exploited by sending a GET request to "/MOXA_CFG2.ini" without a cookie header, causing a null pointer dereference.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-14436 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates