Daily Tech News, Interviews, Reviews and Updates

Vulnerabilities found in Moxa device, can allow attackers to cause disruption

On Thursday, two crucial flaws were discovered in the industrial connectivity device made by Moxa that can let hackers cause significant disruption.

The Taiwan-based industrial networking and automation solutions provider has addressed the flaws.

The two security holes tracked as CVE-2022-2043 and CVE-2022-2044 and rated high severity, impacts Moxa’s NPort 5110 device servers, which are planned for connecting serial devices to Ethernet networks. The flaws can be exploited by a hacker to cause the targeted device to enter a denial of service (DoS) condition.

Moxa and the US Cybersecurity and Infrastructure Security Agency (CISA) release advisories for the vulnerabilities. Moxa claims that only firmware version 2.10 is impacted and instructed customers to contact the tech support department for help.

CISA told impacted organizations to contact Moxa for a security patch. Moxa and CISA have credited, a researcher at Denmark-based industrial cybersecurity company En Garde Security, Jens Nielsen for reporting the vulnerabilities.

En Garde Security owner Mikael Vingaard says that his company’s research department found the vulnerabilities in the first half of March 2022, when the vendor was provided with proof-of-concept (PoC) scripts and videos that show exploitation.

While Moxa NPort devices should not be exposed to the internet, in reality, many are accessible from the web, Vingaard told SecurityWeek. A Shodan search shows that more than 5,000 devices and while there may be some honeypots, Vingaard believes that they all cannot be honeypots.



Readers like you help support The Tech Outlook. When you make a purchase using links on our site, we may earn an affiliate commission. We cannot guarantee the Product information shown is 100% accurate and we advise you to check the product listing on the original manufacturer website. Thetechoutlook is not responsible for price changes carried out by retailers. The discounted price or deal mentioned in this item was available at the time of writing and may be subject to time restrictions and/or limited unit availability. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates Read More
You might also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More