Industrial Alert: Critical Auth Bypass (CVSS 9.2) Hits Moxa Switches
ID: c7ddddc3-772f-5e3a-8503-4738e60e1638
STIX ID: report--c7ddddc3-772f-5e3a-8503-4738e60e1638
Feed Name: securityonline.info
Threat Score
Moxa issued a high-severity advisory for CVE-2024-12297, an authentication bypass in multiple industrial Ethernet switch series (notably TN-A, TN-4500A, TN-5500A, TN-G and variants) with a CVSS 9.2 rating; the flaw in frontend authorization logic may allow brute-force or MD5-collision attacks to bypass authentication, and Moxa has released patches while recommending network segmentation, restricted access, and secure remote access as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
