EDS-405A/408A Series Multiple Web Vulnerabilities

Published: June 27, 2024

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple web server vulnerabilities affect EDS-405A version 3.5 and earlier, as well as EDS-408A Series version 3.6 and earlier. These vulnerabilities arise from insufficient input validation and improper privilege management. An attacker could exploit these vulnerabilities by sending crafted HTTP input to the web service. Successful exploitation could lead to a denial-of-service attack, remote code execution, and privilege escalation. 

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1

Improper Privilege Management (CWE-269) 

CVE-2015-6464

An attacker could send crafted input to escalate privileges. 
2

Uncontrolled Resource Exhaustion (CWE-400) 

CVE-2015-6465 

The embedded GoAhead web server running on the EDS-405A and EDS-408A is vulnerable to a denial-of-service attack. 
3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) 

CVE-2015-6466 

An input field in the administrative web interface lacks input validation, which could be abused to inject JavaScript code. 

Vulnerability Scoring Details 

ID
CVSS v2.0
Vector
Unauthenticated Remote Exploit
CVE-2015-6464 

8.2

AV:N/AC:L/Au:S/C:N/I:C/A:C  No 
CVE-2015-6465 6.8  AV:N/AC:L/Au:S/C:N/I:N/A:C  No 
CVE-2015-6466 4.3  AV:N/AC:M/Au:N/C:N/I:P/A:N  Yes

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-154603-eds-405a-408a-series-multiple-web-vulnerabilities