Multiple Moxa Ethernet switches are affected by the CVE-2023-48795 and CVE-2019-20372 vulnerabilities. These vulnerabilities pose potential security risks that could impact the integrity and functionality of the affected products.
The identified vulnerability types and potential impacts are listed below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Validation of Integrity Check Value (CWE-354) CVE-2023-48795 |
This can allow a remote, man-in-the-middle attacker to bypass integrity checks and downgrade the connection's security. |
| 2 |
Inconsistent Interpretation of HTTP Requests (‘HTTP Request/Response Smuggling’) (CWE-444) CVE-2019-20372 |
This can allow HTTP request smuggling, leading to unauthorized access to web pages, bypassing security controls, and potential for further attacks. |
Vulnerability Scoring Details
|
ID
|
CVSS
|
Vector
|
Unauthenticated Remote Exploits |
|---|---|---|---|
| CVE-2023-48795 |
5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Yes |
| CVE-2019-20372 | 5.3 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-244252-multiple-moxa-ethernet-switches-affected-by-cve-2023-48795-and-cve-2019-20372