AIG-301 Series Azure uAMQP Vulnerabilities

Published: April 22, 2024

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

The AIG-301 Series prior to version 1.5 is affected by multiple Azure uAMQP vulnerabilities. Successful exploitation of these vulnerabilities could remote code execution.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1
Double free (CWE-415)
CVE-2024-27099
An attacker can process an incorrect `AMQP_VALUE` failed state that may cause a double free problem. This may cause an RCE.
2

Improper Control of Generation of Code ('Code Injection') (CWE-97)

CVE-2024-25110

An attacker can trigger a use-after-free issue and may cause a remote code execution.
3

Improper Control of Generation of Code ('Code Injection') (CWE-97)

CVE-2024-21646

An attacker may craft binary type data. An integer overflow, or wraparound, or memory safety issue can occur and may cause remote code execution.

 

Vulnerability Scoring Details 

ID 

CVSS 

Vector 

Severity 

Remote Exploit without Auth? 

CVE-2024-27099

9.8

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 

Critical 

Yes

CVE-2024-25110 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Critical Yes
CVE-2024-21646 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Critical Yes

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-248041-aig-301-series-azure-uamqp-vulnerabilities