CVE-2024-4739: MXsecurity License Generation Function Disclosure
Published Oct 18, 2024
·Updated
The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacker can pose as an authorized user and successfully access the resource.
Affected Software
1 affected component
MOXA Mxsecurity<=1.1.0
Remediation
Information
Moxa has developed an appropriate solution to address the vulnerability. The solution for the affected product is shown below.
* MXsecurity: Please Upgrade to the firmware version 2.2.0 or higher via the Moxa Software Licensing Portal https://netsecuritylicense.moxa.com/Account/Login
Event History
Oct 18, 2024
CVE Published
via MITRE·08:11 AM
Data Sourced
via MITRE·08:11 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-4739?
CVE-2024-4739 is classified as a high severity vulnerability due to unauthorized access potential.
2
How do I fix CVE-2024-4739?
To fix CVE-2024-4739, upgrade to a version of MXsecurity software later than v1.1.0.
3
What causes CVE-2024-4739?
CVE-2024-4739 is caused by a lack of access restriction to resources, allowing unauthorized users to exploit the vulnerability.
4
Which software versions are affected by CVE-2024-4739?
MXsecurity software versions v1.1.0 and prior are affected by CVE-2024-4739.
5
Can an attacker exploit CVE-2024-4739 without authentication?
No, an attacker must acquire a valid authenticator to exploit CVE-2024-4739.