Multiple product vulnerabilities were identified in Moxa’s EDS-G516E and EDS-510E Series Ethernet Switches. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Stack-based buffer overflow (CWE-121), CVE-2020-7007 |
|
| 2 | Use of a broken or risky cryptographic algorithm (CWE-327), CVE-2020-7001 |
|
| 3 | Use of a hard-coded cryptographic key (CWE-321), CVE-2020-6979 | Using a hard-coded cryptographic key may increase the possibility that confidential data can be recovered. |
| 4 | Use of a hard-coded password (CWE-798), CVE-2020-6981 | A user with malicious intent may gain access to the system without proper authentication. |
| 5 | Buffer Copy without Checking Size of Input (CWE-120), CVE-2020-6999 |
|
| 6 | User credentials are sent in clear text (CWE-319), CVE-2020-6997 | To exploit this vulnerability, the attacker may intercept the information from the clear text communication. |
| 7 | Weak password requirements (CWE-521), CVE-2020-6991 | A user with malicious intent may try to retrieve credentials by using brute force. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/eds-g516e-510e-ethernet-switches-vulnerabilities