CVE-2024-12297
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
- EPSS probability
- 0.85%
- CWE
- CWE-656
- Published
- 2025-01-15
- Last modified
- 2026-03-13
Affected products
- Moxa EDS-508A Series
- Moxa PT-508 Series
- Moxa PT-510 Series
- Moxa PT-7528 Series
- Moxa PT-7728 Series
- Moxa PT-7828 Series
- Moxa PT-G503 Series
- Moxa PT-G510 Series
Weakness type
Related vulnerabilities
- CVE-2026-7161 — GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability
- CVE-2026-42363 — GeoVision GV-IP Device Utility Device Authentication insufficient encryption vulnerability
- CVE-2025-59093 — Insecure Password Derivation Function for Database Administrator in dormakaba Kaba exos 9300
- CVE-2025-7020 — BYD DiLink OS Incorrect encryption Implementation of system log dumps
- CVE-2024-9138 — Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliances
- CVE-2024-5244 — TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability
- CVE-2020-10286 — RVD#3323: Mismanaged permission implementation leads to privilege escalation, exfiltration of sensitive information, and DoS
- CVE-2020-10284 — RVD#3321: No Authentication required to exert manual control of the robot