logo

Critical Alert: Moxa Switches Exposed to OpenSSH Remote Code Execution (CVSS 9.8)

ID: bdd93d1e-4a4e-58f7-8676-ca17d4d3cf70

STIX ID: report--bdd93d1e-4a4e-58f7-8676-ca17d4d3cf70

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical OpenSSH vulnerability (CVE-2023-38408, CVSS 9.8) affecting the PKCS#11 feature in ssh-agent has been identified in Moxa industrial ethernet switches (EDS and RKS series). The flaw can enable remote code execution due to an unreliable search path and an incomplete prior fix; affected models and firmware versions are listed, vendor patches (v4.1.58 for EDS, v5.0.4 for RKS) must be requested from Moxa Support, and mitigation recommendations (network segregation, access restrictions, MFA, encrypted remote access, monitoring) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.