First published: Thu Nov 16 2017(Updated: )
A Resource Exhaustion issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version 2.6, NPort 5110 Version 2.7, NPort 5130 Version 3.7 and prior, and NPort 5150 Version 3.7 and prior. An attacker may be able to exhaust memory resources by sending a large amount of TCP SYN packets.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport 5110 Firmware | =2.2 | |
Moxa Nport 5110 Firmware | =2.4 | |
Moxa Nport 5110 Firmware | =2.6 | |
Moxa Nport 5110 Firmware | =2.7 | |
Moxa NPort 5110 | ||
Moxa Nport 5130 Firmware | <=3.7 | |
Moxa Nport 5130 | ||
Moxa Nport 5150 Firmware | <=3.7 | |
Moxa Nport 5150 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14028 is a Resource Exhaustion vulnerability discovered in Moxa NPort 5110, NPort 5130, and NPort 5150 devices.
CVE-2017-14028 has a severity score of 7.5, which is considered high.
The affected software for CVE-2017-14028 includes Moxa NPort 5110 firmware versions 2.2, 2.4, 2.6, and 2.7, NPort 5130 firmware up to and including version 3.7, and NPort 5150 firmware up to and including version 3.7.
An attacker can exploit CVE-2017-14028 by sending a large amount of malicious data to the affected Moxa NPort devices, leading to resource exhaustion and potential denial of service.
Yes, Moxa NPort 5110, NPort 5130, and NPort 5150 devices are vulnerable to CVE-2017-14028 if they are running the affected firmware versions.