PT-2026-48857 · Moxa · Embedded Linux Firmware
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moxa embedded Linux firmware for industrial computers and controllers (affected versions not specified)
Description
A missing required cryptographic step exists in the embedded Linux firmware. This issue is an incomplete remediation of a previous flaw where TPM2 parameter encryption was introduced as a countermeasure. Due to an omission in the authorization session configuration, the parameter encryption is ineffective. An attacker with invasive physical access can capture TPM communications on the SPI bus to derive the LUKS disk encryption key in plaintext, leading to a full compromise of the encrypted disk volume. Remote exploitation is not possible.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Embedded Linux Firmware