PT-2020-15628 · Moog · Moog Exo Series

Gabriel Gonzalez

+3

·

Published

2020-08-21

·

Updated

2021-07-21

·

CVE-2020-24051

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moog EXO Series versions EXVF5C-2 and EXVP7C2-3
Description A security issue was found in the Moog EXO Series units that support the ONVIF interoperability protocol. The authentication check for certain ONVIF operations can be bypassed, allowing an attacker to execute privileged operations without authentication. This could enable the creation of a new Administrator user.
Recommendations For Moog EXO Series versions EXVF5C-2 and EXVP7C2-3, as a temporary workaround, consider disabling the ONVIF protocol until a patch is available. Restrict access to privileged operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24051

Affected Products

Moog Exo Series