Security Enhancements in the EDS-P510 Series – Modbus/TCP Access, Device Identification, and Unencrypted Telnet Server

Published: November 8, 2024

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

The EDS-P510 Series has been enhanced to address several key vulnerabilities:

  1. Modbus/TCP Coil Access: Attackers could read and analyze coil settings, which may allow them to alter device functions in SCADA and DCS environments.
  2. Modbus/TCP Device Identification: Attackers could retrieve device details via Modbus MEI read requests, potentially exposing Vendor Name, Product Code, and other identifying information.
  3. Unencrypted Telnet Server: Using Telnet over an unencrypted channel can expose sensitive information, such as credentials, to interception. SSH is recommended as a secure alternative.

These updates aim to improve the EDS-P510 Series’ resilience against vulnerabilities, thereby enhancing its overall security.

Vulnerability Scoring Details 

Vulnerability
Base Score
Vector

Unauthenticated Remote Exploits

Modbus/TCP Device Identification

CVSS 3.1: 5.8

AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Yes
Modbus/TCP Coil Access CVSS 3.1: 5.3 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Yes

Unencrypted Telnet Server

CVSS 3.1: 6.5

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Yes

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241021-vulnerability-identified-in-the-eds-p510-series-modbustcp,-device-identification,-and-unencrypted-telnet