CVE-2024-12297: Frontend Authorization Logic Disclosure Vulnerability
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12297?
CVE-2024-12297 is classified as a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-12297?
To fix CVE-2024-12297, update the Moxa Ethernet Switch EDS-508A Series firmware to a version later than 3.11.
What type of vulnerability is CVE-2024-12297?
CVE-2024-12297 is an authentication bypass vulnerability that affects the authorization process of the device.
Which devices are affected by CVE-2024-12297?
CVE-2024-12297 affects the Moxa Ethernet switch EDS-508A Series running firmware version 3.11 and earlier.
Can CVE-2024-12297 lead to further exploitation?
Yes, an attacker exploiting CVE-2024-12297 can gain unauthorized access, potentially leading to further exploitation of the network.