CVE-2024-9137: Missing Authentication Vulnerability in Ethernet Switches

Published: January 17, 2025

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Moxa’s Ethernet switches are affected by a critical vulnerability, CVE-2024-9137, which could result in unauthorized access and system compromise. This vulnerability allows attackers to manipulate device configurations without requiring authentication. Given the significant security risks, immediate action is strongly recommended to mitigate potential exploitation.

The identified vulnerability types and potential impacts are listed below:

Item Vulnerability Type Impact
1

CWE-306: Missing Authentication for Critical Function (CVE-2024-9137)

The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

Vulnerability Scoring Details 

ID Base Score Vector Unauthenticated Remote Exploits
CVE-2024-9137 CVSS 3.1: 9.4

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Yes
CVSS 4.0: 8.8

AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

Note: This advisory uses CVSS 3.1 as the standard for determining severity levels. CVSS 4.0 is provided as a reference metric for comparison.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241156-cve-2024-9137-missing-authentication-vulnerability-in-ethernet-switches