Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)
ID: bdd93d1e-4a4e-58f7-8676-ca17d4d3cf70
STIX ID: report--bdd93d1e-4a4e-58f7-8676-ca17d4d3cf70
Feed Name: securityonline.info
A critical OpenSSH vulnerability (CVE-2023-38408, CVSS 9.8) affecting the PKCS#11 feature in ssh-agent has been identified in Moxa industrial ethernet switches (EDS and RKS series). The flaw can enable remote code execution due to an unreliable search path and an incomplete prior fix; affected models and firmware versions are listed, vendor patches (v4.1.58 for EDS, v5.0.4 for RKS) must be requested from Moxa Support, and mitigation recommendations (network segregation, access restrictions, MFA, encrypted remote access, monitoring) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
