Moxa UC Series Improper Physical Access Control Vulnerability

Published: November 29, 2022

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Successful exploitation of the improper physical access control vulnerability could allow an attacker who has gained physical access to the device to take full control using the console port.

In order for this vulnerability to be exploited, an attacker has to use a cable to access the device’s bootloader menu. Therefore, the device is vulnerable if it is deployed in an area without proper physical security (e.g., in an open space without access control).

Moxa’s PSIRT would like to remind organizations to perform a proper impact analysis and risk assessment prior to deploying defensive measures, such as the security patch.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Improper Physical Access Control
(CVE 2023-1257)
An attacker with physical access to the device can restart the device and gain access to its BIOS. Then, command line options can be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device authentication files to create a new user profile and gain full access to the system.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/uc-series-improper-physical-access-control-vulnerability