AWK-3121 Series Industrial AP/Bridge/Client Vulnerabilities

Published: December 2, 2019

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple product vulnerabilities were identified in Moxa’s AWK-3121 Series. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
CVE-2018-10697, CVE-2018-10699
Multiple parameters are susceptible to command injection
2 Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77)
CVE-2018-10702
Specified parameter is susceptible to command injection via shell metacharacters
3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
CVE-2018-10692
Vulnerable to cross-site scripting attack to steal the cookie
4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79)
CVE-2018-10700
Specified parameter is susceptible to XSS payload injection
5 Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119)
CVE-2018-10693, CVE-2018-10695, CVE-2018-10701, and CVE-2018-10703
Multiple parameters are susceptible to buffer overflow
6 Credentials Management (CWE-255) CVE-2018-10690 The device by default allows HTTP traffic thus providing an insecure communication mechanism for a user connecting to the web server
7 Credentials Management (CWE-255) CVE-2018-10694 The device provides a Wi-Fi connection that is open and does not use any encryption mechanism by default
8 Credentials Management (CWE-255) CVE-2018-10698 The device enables an unencrypted TELNET service by default
9 Improper Access Control (CWE-284) CVE-2018-10691 Vulnerable to unauthorized systemlog.log download
10 Cross-Site Request Forgery (CSRF) (CWE-352) CVE-2018-10696 Web interface is not protected against CSRF attacks

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/awk-3121-series-industrial-ap-bridge-client-vulnerabilities