Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp78-8mxr-44qr

Опубликовано: 15 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.2

Описание

Moxa’s Ethernet switch EDS-508A Series, running firmware version 3.11 and earlier, is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

Moxa’s Ethernet switch EDS-508A Series, running firmware version 3.11 and earlier, is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

EPSS

Процентиль: 44%
0.00216
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-656

Связанные уязвимости

nvd
около 1 года назад

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

CVSS3: 10
fstec
около 1 года назад

Уязвимость реализации механизма авторизации микропрограммного обеспечения коммутаторов Moxa EDS-508A, позволяющая нарушителю получить несанкционированный доступ к конфигурационным файлам устройства

EPSS

Процентиль: 44%
0.00216
Низкий

9.2 Critical

CVSS4

Дефекты

CWE-656