The EDS-P510 Series has been enhanced to address several key vulnerabilities:
- Modbus/TCP Coil Access: Attackers could read and analyze coil settings, which may allow them to alter device functions in SCADA and DCS environments.
- Modbus/TCP Device Identification: Attackers could retrieve device details via Modbus MEI read requests, potentially exposing Vendor Name, Product Code, and other identifying information.
- Unencrypted Telnet Server: Using Telnet over an unencrypted channel can expose sensitive information, such as credentials, to interception. SSH is recommended as a secure alternative.
These updates aim to improve the EDS-P510 Series’ resilience against vulnerabilities, thereby enhancing its overall security.
Vulnerability Scoring Details
| Vulnerability |
Base Score
|
Vector
|
Unauthenticated Remote Exploits |
|---|---|---|---|
|
Modbus/TCP Device Identification |
CVSS 3.1: 5.8 |
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Yes |
| Modbus/TCP Coil Access | CVSS 3.1: 5.3 | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | Yes |
|
Unencrypted Telnet Server |
CVSS 3.1: 6.5 |
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241021-vulnerability-identified-in-the-eds-p510-series-modbustcp,-device-identification,-and-unencrypted-telnet