Moxa Switches Vulnerability Enables Unauthorized Access through Authentication Bypass
Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches. This vulnerability, identified as CVE-2024-12297, permits remote attackers to bypass authentication mechanisms,…
Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches. This vulnerability, identified as CVE-2024-12297, permits remote attackers to bypass authentication mechanisms, potentially allowing unauthorized access to critical network infrastructure. With a CVSS v4.0 score of 9.2, it is classified as critical, necessitating immediate attention from administrators overseeing operational technology (OT) environments.
The vulnerability is rooted in a flaw within the frontend authorization logic of the affected devices. Identified as CWE-656 (Reliance on Security Through Obscurity), the flaw affects the manner in which the switches verify user credentials. Despite utilizing both client-side and back-end server verification, the implementation contains weaknesses exploitable by attackers.
Exploitation of these flaws allows an unauthenticated attacker to perform password brute-forcing (CAPEC-49) or utilize MD5 collision attacks to forge authentication hashes. Successful exploitation results in bypassing the login screen, leading to full device compromise. Given the role of these switches in industrial networks, such access could allow threat actors to disrupt operations, intercept traffic, or move laterally to other critical assets within the OT network.
CVE ID CVSS v4.0 Score Vector Impact
CVE-2024-12297 9.2 (Critical) AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L Authentication Bypass, Unauthorized Access
Moxa has released a critical security advisory concerning a significant vulnerability in multiple series of its industrial Ethernet switches.
The vulnerability affects the TN-A and TN-G series of managed Ethernet switches. Moxa has released specific patch versions to address the flaw. These patches must be obtained by contacting Moxa Technical Support directly.
Product Series Affected Versions Remediation (Patch Version)
TN-A Series (TN-4500A, TN-5500A) Firmware v4.1 and earlier Contact Support for v3.13.255
TN-G Series (TN-G4500, TN-G6500) Firmware v5.5 and earlier Contact Support for v5.5.255
Mitigation and Security Best Practices
For organizations unable to immediately apply the firmware updates, Moxa recommends a defense-in-depth approach to mitigate the risk of exploitation:
Network Segmentation: Utilize VLANs and physical separation to isolate operational networks from enterprise traffic. Access Control: Implement Access Control Lists (ACLs) and firewalls to restrict device management interfaces to trusted IP addresses only. Disable Internet Exposure: Ensure these switches are not directly exposed to the public internet. VPN Usage: Mandate encrypted communication protocols (SSH, VPN) for all remote management tasks. Log Monitoring: Enable event logging and regularly audit trails for anomalies, specifically focusing on repeated failed login attempts or unauthorized access indicators.
Administrators are advised to apply the relevant patches immediately to prevent potential brute-force or hash collision attacks against their industrial infrastructure.
Based on reporting by GBHackers.
