ID

VAR-202309-2835


TITLE

MOXA E1242 Ethernet IO Server has unauthorized access vulnerability

Trust: 0.6

sources: CNVD: CNVD-2023-83385

DESCRIPTION

Mosa Technology (Shanghai) Co., Ltd. is an enterprise mainly engaged in professional technical services. There is an unauthorized access vulnerability in the MOXA E1242 Ethernet IO Server. An attacker can use this vulnerability to obtain sensitive information.

Trust: 0.6

sources: CNVD: CNVD-2023-83385

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2023-83385

AFFECTED PRODUCTS

vendor:moxamodel:e1242 ethernet io serverscope:eqversion:2.5

Trust: 0.6

vendor:moxamodel:e1242 ethernet io serverscope:eqversion:3.2

Trust: 0.6

sources: CNVD: CNVD-2023-83385

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2023-83385
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2023-83385
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2023-83385

PATCH

title:Patch for MOXA E1242 Ethernet IO Server has unauthorized access vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/472141

Trust: 0.6

sources: CNVD: CNVD-2023-83385

EXTERNAL IDS

db:CNVDid:CNVD-2023-83385

Trust: 0.6

sources: CNVD: CNVD-2023-83385

SOURCES

db:CNVDid:CNVD-2023-83385

LAST UPDATE DATE

2023-11-21T05:25:24.009000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2023-83385date:2023-11-03T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2023-83385date:2023-09-12T00:00:00