PT-2017-3802 · Moxa · Moxa Ioxpress+1

Published

2017-05-09

·

Updated

2020-03-26

·

CVE-2019-18242

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Moxa ioLogik 2500 series firmware versions 3.0 or lower Moxa IOxpress configuration utility versions 2.3.0 or lower
Description The issue is related to an uncontrolled resource consumption in the firmware of Moxa ioLogik 2542-HSPA modules and the Moxa IOxpress Configuration Utility. This can be exploited by a remote attacker using specially crafted packets, potentially leading to a denial of service. Frequent and multiple requests for short-term use may cause the web server to fail.
Recommendations For Moxa ioLogik 2500 series firmware versions 3.0 or lower, consider restricting access to the web server to minimize the risk of exploitation until a patch is available. For Moxa IOxpress configuration utility versions 2.3.0 or lower, avoid using the utility for frequent and multiple requests for short-term use until the issue is resolved. As a temporary workaround, consider disabling the web server functionality in the affected firmware and utility until a patch is available.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03265
CVE-2019-18242

Affected Products

Moxa Ioxpress
Moxa Iologik 2500