PT-7528 and PT-7828 Series Ethernet Switches Vulnerabilities

Published: September 25, 2019

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple product vulnerabilities were identified in Moxa’s PT-7528 and PT-7828 Series Ethernet Switches. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Stack-based buffer overflow (CWE-121), CVE-2020-6989 The attacker may execute arbitrary codes or target the device to cause it to go out of service.
2 Use of a broken or risky cryptographic algorithm (CWE-327), CVE-2020-6987 / CNVD-2020-13511 Using a weak cryptographic algorithm may allow confidential information to be disclosed.
3 Use of a broken or risky cryptographic algorithm (CWE-327), CVE-2020-6987 / CNVD-2020-13511 Improper implementation of the cryptographic function may allow confidential information to be disclosed.
4 Use of a hard-coded cryptographic key (CWE-321), CVE-2020-6983 / CNVD-2020-13512 Using a hard-coded cryptographic key increases the possibility that confidential data can be recovered.
5 Use of a hard-coded password (CWE-798), CVE-2020-6985 / CNVD-2020-13513 A user with malicious intent may gain access to the system without proper authentication.
6 Weak password requirements (CWE-521), CVE-2020-6995 / CNVD-2020-13514 A user with malicious intent may try to retrieve credentials by using brute force.
7 Information exposure (CWE-200), CVE-2020-6993 / CNVD-2020-13507 A user with malicious intent could steal sensitive information by performing a zero-day attack.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/pt-7528-7828-ethernet-switches-vulnerabilities