Multiple product vulnerabilities were identified in Moxa’s ioLogik 2542-HSPA Series Controllers and I/Os, and IOxpress Configuration Utility. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Use Weak Cryptographic Algorithms (CWE-310), CVE-2018-18238 | The configuration file was not encrypted. If an attacker got hold of the file, sensitive information in the device could be disclosed. |
| 2 | Cleartext Storage and Transmission of Sensitive Information (CWE-312 and CWE-319), CVE-2020-7003 | The configuration file was not encrypted. If an attacker got hold of the file, sensitive information in the device could be disclosed. |
| 3 | Denial-of-service attack (CWE-400, CWE-941), CVE-2019-18242 | Frequent and multiple requests for short-term use may cause the web server to fail. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/iologik-2542-hspa-series-ioxpress-vulnerabilities