MXsecurity Series Multiple Vulnerabilities

Published: September 1, 2023

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

These vulnerabilities are caused by the improper design or implementation of authentication mechanisms and input validation. Exploiting these vulnerabilities could enable an attacker to bypass authentication, which could lead to the unauthorized disclosure or tampering of authenticated information, unauthorized access to sensitive data, and remote access without proper authorization.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1
Small Space of Random Values (CWE-334)
CVE-2023-39979
An attacker can bypass authentication to gain unauthorized access.
2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
CVE-2023-39980
An attacker can change the SQL command to gain unauthorized access to disclose information.
3
Improper Authentication (CWE-287)
CVE-2023-39981
An attacker can gain unauthorized access to disclose device information.
4
Use of Hard-coded Credentials (CWE-798)
CVE-2023-39982
An attacker can facilitate man-in-the-middle attacks and enable the decryption of SSH traffic.
5
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915)

CVE-2023-39983

An attacker can register/add a device via the nsm-web application.

 

Vulnerability Scoring Details

ID CVSS V3.1 VECTOR REMOTE EXPLOIT WITHOUT AUTH?
CVE-2023-39979 9.8 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Yes
CVE-2023-39980 7.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N No
CVE-2023-39981 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Yes
CVE-2023-39982 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Yes
CVE-2023-39983 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Yes

 

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230403-mxsecurity-series-multiple-vulnerabilities