CVE-2024-4740: MXsecurity Use of Hard-coded Credentials
Published Oct 18, 2024
·Updated
MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerability could allow an attacker to tamper with sensitive data.
Affected Software
1 affected component
MOXA Mxsecurity<=1.1.0
Remediation
Information
Moxa has developed an appropriate solution to address the vulnerability. The solution for the affected product is shown below.
* MXsecurity: Please upgrade to the firmware version 2.2.0 or higher via the Moxa Software Licensing Portal https://netsecuritylicense.moxa.com/Account/Login
Event History
Oct 18, 2024
CVE Published
via MITRE·08:21 AM
Data Sourced
via MITRE·08:21 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-4740?
CVE-2024-4740 has a high severity rating due to the exploitation of hard-coded credentials.
2
How do I fix CVE-2024-4740?
To fix CVE-2024-4740, update the MXsecurity software to version 1.1.1 or later, which eliminates the use of hard-coded credentials.
3
What are the risks associated with CVE-2024-4740?
The risks associated with CVE-2024-4740 include potential unauthorized access to sensitive data and the possibility of data tampering.
4
Which versions of Moxa MXsecurity are affected by CVE-2024-4740?
All Moxa MXsecurity software versions v1.1.0 and prior are affected by CVE-2024-4740.
5
Can CVE-2024-4740 be exploited remotely?
Yes, CVE-2024-4740 can be exploited remotely if an attacker obtains the hard-coded credentials.