Multiple product vulnerabilities were identified in Moxa’s ioLogik E2200 Series Controllers and I/Os, and ioAdmin Configuration Utility. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types for the ioLogik E2200 Series and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Improper Authentication (CWE-285) and Use of Client-side Authentication (CWE-603) BDU:2021-05548 |
An attacker can form a special network package to obtain authorization information or even bypass the authentication check. |
| 2 | Use of Hard-coded Password (CWE-259) BDU:2021-05549 |
Malicious users can gain access through the hard-coded password. |
| 3 | Improper Access Control (CWE-284) BDU:2021-05550 |
Does not restrict or incorrectly restricts unauthorized access. |
| 4 | Stack-based Buffer Overflow (CWE-121) BDU:2021-05551 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE). |
| 5 | Buffer Copy Without Checking Size of Input (CWE-120) BDU:2021-05552 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack. |
| 6 | Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285) BDU:2021-05553 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization. |
| 7 | Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285) BDU:2021-05554 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization. |
| 8 | Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285) BDU:2021-05555 |
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization. |
The identified vulnerability types for ioAdmin Configuration Utility and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 9 | Weak Password Requirements (CWE-521) BDU:2021-05556 |
Weak password requirements may allow an attacker to use brute force to gain access to the device. |
| 10 | Improper Restriction of Excessive Authentication Attempts (CWE-307) BDU:2021-05557 |
Weak password requirements may allow an attacker to use brute force to gain access to the device. |
| 11 | Cleartext Storage of Sensitive Information in Memory (CWE-316) BDU:2021-05558 |
An attacker can use malware to obtain sensitive data stored in the device’s memory. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/iologik-e2200-ioadmin-configuration-utility-vulnerabilities