# CVE-2024-12297

## Summary

- **CVE ID:** CVE-2024-12297
- **Severity:** CRITICAL
- **CVSS Score:** 9.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L)
- **CWE:** CWE-656
- **Published:** Jan 15, 2025
- **Last Modified:** Mar 13, 2026

## Description

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

## Affected Products

- Moxa — EDS-508A Series (1.0)
- Moxa — PT-508 Series (1.0)
- Moxa — PT-510 Series (1.0)
- Moxa — PT-7528 Series (1.0)
- Moxa — PT-7728 Series (1.0)
- Moxa — PT-7828 Series (1.0)
- Moxa — PT-G503 Series (1.0)
- Moxa — PT-G510 Series (1.0)
- Moxa — PT-G7728 Series (1.0)
- Moxa — PT-G7828 Series (1.0)

## References

- [CNA](https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241407-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-in-eds-508a-series)
- [CNA](https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.85%
- **EPSS Percentile:** 56.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._