PT-2025-1115 · Moxa · Moxa Eds-508A Series

Artem Turyshev

·

Published

2025-01-15

·

Updated

2026-02-05

·

CVE-2024-12297

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Name of the Vulnerable Software and Affected Versions Moxa EDS-508A Series versions 3.11 and earlier
Description The Moxa EDS-508A Series Ethernet switch is vulnerable to an authentication bypass due to flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.
Recommendations For Moxa EDS-508A Series versions 3.11 and earlier, a patch is available for affected devices. It is recommended to apply this patch to fix the vulnerability. As a temporary workaround, consider restricting access to the device and its network to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00371
CVE-2024-12297

Affected Products

Moxa Eds-508A Series