Moxa has verified that some of its products are impacted by the GNU Bourne-Again Shell (Bash) vulnerability (CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277, and CVE 2014-6278). Also known as “Shellshock,” this vulnerability could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system.
Moxa's Cyber Security Response Team (CSRT) is fully engaged in this matter and we are taking appropriate action. If there are any updates to the status of the vulnerabilities or how these affect Moxa's products, we will provide an update immediately.
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/moxas-response-regarding-the-gnu-bourne-again-shell-bash-vulnerability-shellshock