Moxa’s Ethernet switches are affected by a critical vulnerability, CVE-2024-9137, which could result in unauthorized access and system compromise. This vulnerability allows attackers to manipulate device configurations without requiring authentication. Given the significant security risks, immediate action is strongly recommended to mitigate potential exploitation.
The identified vulnerability types and potential impacts are listed below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
CWE-306: Missing Authentication for Critical Function (CVE-2024-9137) |
The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise. |
Vulnerability Scoring Details
| ID | Base Score | Vector | Unauthenticated Remote Exploits |
|---|---|---|---|
| CVE-2024-9137 | CVSS 3.1: 9.4 |
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Yes |
| CVSS 4.0: 8.8 |
AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N |
Note: This advisory uses CVSS 3.1 as the standard for determining severity levels. CVSS 4.0 is provided as a reference metric for comparison.
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241156-cve-2024-9137-missing-authentication-vulnerability-in-ethernet-switches