EDS-405A Series, EDS-408A Series, EDS-510A Series, and IKS-G6824A Series Ethernet Switches Vulnerabilities

Published: February 1, 2019

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple product vulnerabilities were identified in Moxa’s EDS-405A Series, EDS-408A Series, EDS-510A Series, and IKS-G6824A Series Ethernet Switches. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

EDS-405A Series, EDS-408A Series, and EDS-510A Series

Item Vulnerability Type Impact
1

Plain text storage of a password

(CVE-2019-6518)

Moxa EDS industrial switches store plaintext passwords, which would be exposed by read raw configuration function of proprietary protocol.
2

Predictable session ID

(CVE-2019-6563)

Moxa EDS industrial switches web server cookie value is not generated with proper encryption. Therefore, an attacker can still reuse it to recover the administrator's password.
Note: EDS-510A users do not need to upgrade the patched firmware; please visit the Solutions section for the mitigation.
3

Missing encryption of sensitive data

(CVE-2019-6526)

The proprietary management protocols that are used by Moxa EDS industrial switches may be exploited to reveal an administrative password.
4

Improper restriction of excessive authentication attempts

(CVE-2019-6524)

Moxa EDS industrial switches do not implement sufficient measures to prevent multiple failed authentication attempts, which makes the switches susceptible to brute force attacks.
5

Resource exhaustion

(CVE-2019-6559)

Moxa EDS industrial switches use proprietary protocols, which allow authenticated users with remote access to cause a denial of service via a specially crafted packet.

 

IKS-G6824A Series

Item Vulnerability Type Impact
1

Buffer overflow in account setting parameters

(CVE-2019-6557)

Improper calculation of length of cookie value leads to stack overflow, which gives an attacker an ability to cause device reboot or perform code execution.
2

Buffer overflow in multiple parameters

(CVE-2019-6557)

Several buffer overflow vulnerabilities can be caused by copying the unregulated contents of specific parameters, which in turn may allow remote code execution or cause device reboot.
3

Read device memory

(CVE-2019-6522)

Failure to properly check array bounds gives attackers the ability to read device memory on arbitrary addresses.
4

Failure to handle corrupted OSPF packets

(CVE-2019-6559)

Sending malformed OSPF Hello packets to a vulnerable device results in the device rebooting after 2 or 3 minutes.
5

Multiple XSS

(CVE-2019-6565)

Failure to properly validate user input gives unauthenticated and authenticated attackers the ability to perform XSS attacks on users.

6

Improper web interface access control

(CVE-2019-6520)

The switch has a management web interface. However, the authority is not properly checked from the server side, which results in read-only users being able to alter configurations.

7

Cross-Site Request Forgery

(CVE-2019-6561)

Cross-Site Request Forgery (CSRF) occurs when an attacker uses a web browser that has already been authenticated by a user to target a web application.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/eds-405a-series-eds-408a-series-eds-510a-series-and-iks-g6824a-series-ethernet-switches-vulnerabilities