ioLogik E2200 Series Controllers and I/Os, and ioAdmin Configuration Utility Vulnerabilities

Published: November 23, 2021

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple product vulnerabilities were identified in Moxa’s ioLogik E2200 Series Controllers and I/Os, and ioAdmin Configuration Utility. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types for the ioLogik E2200 Series and potential impacts are shown below:

Item Vulnerability Type Impact
1 Improper Authentication (CWE-285) and Use of Client-side Authentication (CWE-603)
BDU:2021-05548
An attacker can form a special network package to obtain authorization information or even bypass the authentication check.
2 Use of Hard-coded Password (CWE-259)
BDU:2021-05549
Malicious users can gain access through the hard-coded password.
3 Improper Access Control (CWE-284)
BDU:2021-05550
Does not restrict or incorrectly restricts unauthorized access.
4 Stack-based Buffer Overflow (CWE-121)
BDU:2021-05551
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE).
5 Buffer Copy Without Checking Size of Input (CWE-120)
BDU:2021-05552
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack.
6 Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285)
BDU:2021-05553
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization.
7 Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285)
BDU:2021-05554
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization.
8 Stack-based Buffer Overflow (CWE-121) and potential Improper Authorization (CWE-285)
BDU:2021-05555
A buffer overflow in the built-in web server allows remote attackers to initiate a DoS attack and execute arbitrary code (RCE), or potentially bypass authorization.

The identified vulnerability types for ioAdmin Configuration Utility and potential impacts are shown below:

Item Vulnerability Type Impact
9 Weak Password Requirements (CWE-521)
BDU:2021-05556
Weak password requirements may allow an attacker to use brute force to gain access to the device.
10 Improper Restriction of Excessive Authentication Attempts (CWE-307)
BDU:2021-05557
Weak password requirements may allow an attacker to use brute force to gain access to the device.
11 Cleartext Storage of Sensitive Information in Memory (CWE-316)
BDU:2021-05558
An attacker can use malware to obtain sensitive data stored in the device’s memory.
 

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/iologik-e2200-ioadmin-configuration-utility-vulnerabilities