Multiple product vulnerabilities were identified in Moxa’s NPort 5000 Series, and NPort 6000 Series Serial Device Server. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Unauthenticated retrievable sensitive account information | Ensure that passwords have been enabled. |
| 2 | Unauthenticated remote firmware update | Ensure that passwords have been enabled. |
| 3 | Buffer overflow | Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability. |
| 4 | Cross-site scription | Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability. |
| 5 | Cross-site request forgery | Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/nport-5000-series-and-nport-6000-series-serial-device-server-vulnerabilities