PT-2017-3801 · Moxa · Moxa Ioxpress Configuration Utility+2

Published

2017-05-09

·

Updated

2022-01-01

·

CVE-2019-18238

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa ioLogik 2542-HSPA versions 3.0 or lower Moxa ioLogik 2500 series firmware versions 3.0 or lower Moxa Ioxpress Configuration Utility versions 2.3.0 or lower
Description The issue is related to the use of the HTTP protocol by default for "Basic HTTP Authorization" in Moxa ioLogik 2542-HSPA and Moxa Ioxpress Configuration Utility. This may allow a remote attacker to intercept administrator credentials and other confidential information, and gain access to the system management. Sensitive information is stored in configuration files without encryption, which may enable an attacker to access an administrative account.
Recommendations For Moxa ioLogik 2542-HSPA versions 3.0 or lower, consider disabling the use of the HTTP protocol for authorization until a secure alternative is implemented. For Moxa ioLogik 2500 series firmware versions 3.0 or lower, update the configuration to store sensitive information with encryption. For Moxa Ioxpress Configuration Utility versions 2.3.0 or lower, restrict access to configuration files to minimize the risk of exploitation. As a temporary workaround, consider restricting access to the system management interface until the issue is resolved.

Fix

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03264
CVE-2019-18238

Affected Products

Moxa Ioxpress Configuration Utility
Moxa Iologik 2500
Moxa Iologik 2542-Hspa