ThingsPro 2 Series System Software Vulnerabilities

Published: October 17, 2018

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

Multiple product vulnerabilities were identified in Moxa’s ThingsPro 2 Series System Software. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 User enumeration A remote attacker can find valid users in web applications and use brute force to exploit this vulnerability to find the corresponding password.
2 User privilege escalation The exploitation of this vulnerability allows the remote attacker to gain more privileges.
3 Broken access control The exploitation of this vulnerability allows the remote attacker to gain more privileges.
4 The server does not require the old password when changing the password It is too easy for a remote attacker to change the password.
5 Cleartext storage of sensitive information The remote attacker can guess the token permissions.
6 Privilege escalation exists on hidden token The remote attacker could gain root privileges and execute commands by accessing the hidden token API.
7 Remote code execution The remote attacker can use this to inject strings and force the server to run additional commands.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/thingspro-2-series-system-software-vulnerabilities