CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-12297

CVSS 9.2v4.0pub. 2025-01-15upd. 2026-04-15

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

🤖 AI Analysis
How it works

The device's authorization mechanism relies on verification on both the client side (frontend) and backend server side, however both layers contain vulnerable implementations. An attacker can perform a brute-force attack to guess valid authentication credentials or exploit an MD5 collision attack to forge hashes used during authentication. Exposed authorization logic on the frontend side additionally facilitates analysis and exploitation of verification process weaknesses.

Impact

Successful exploitation may allow an attacker to take control of the network device without knowledge of valid authentication credentials, threatening the confidentiality, integrity, and availability of the switch.

Mitigation & patch

Apply patches available from the manufacturer according to references (security advisories MPSA-241407 and MPSA-241408 available on the Moxa website). It is also recommended to restrict access to the device management interface exclusively to trusted networks and implement network segmentation for OT/industrial devices.

Who is affected

Moxa network switches from the EDS-508A series and Moxa switches from the PT line — specific firmware versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References