Multiple product vulnerabilities were identified in Moxa’s ioPAC 8500 Series (IEC models) and ioPAC 8600 Series (IEC models) rugged modular programmable controllers. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Relative path traversal (CWE23) CVE-2020-25176 | It is possible for an unauthenticated attacker located remotely to traverse an application’s directory, which could lead to remote code execution. |
| 2 | Cleartext transmission of sensitive information (CWE-319) CVE-2020-25178 | Data is transferred over this protocol unencrypted, which could allow an attacker located remotely to upload, read, and delete files. |
| 3 | Use of hard-coded cryptographic key (CWE-321) CVE-2020-25180 | An unauthenticated attacker located remotely could pass their own encrypted password to the ISaGRAF 5 Runtime, which may result in information disclosure on the device. |
| 4 | Unprotected storage of credentials (CWE-256) CVE-2020-25184 | An unauthenticated attacker at the site could compromise user’s passwords, resulting in information disclosure. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/iopac-8500-and-iopac-8600-series-iec-models-controllers-vulnerabilities