Authentication Bypass Vulnerability in Moxa Ethernet Switch EDS-508A Series
CVE-2024-12297

9.2CRITICAL

Key Information:

Vendor
Moxa
Vendor
CVE Published:
15 January 2025

Summary

The Moxa EDS-508A Series Ethernet switch is prone to an authentication bypass vulnerability due to inadequate authorization mechanisms. Attackers can exploit this weakness to perform brute-force attacks, allowing them to guess valid credentials, or execute MD5 collision attacks to forge authentication hashes. This can severely compromise the security of the device, potentially allowing unauthorized access.

Affected Version(s)

EDS-508A Series 1.0 <= 3.11

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Artem Turyshev from Rosatom Automated Control Systems Joint-Stock Company
.