ID

VAR-202310-2248


CVE

CVE-2023-4929


TITLE

plural  Moxa Inc.  Vulnerability related to insufficient data integrity verification in products

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859

DESCRIPTION

All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices. nport 5150ai-m12-ct-t firmware, nport 5250ai-m12-ct-t firmware, nport 5150ai-m12-t firmware etc. Moxa Inc. The product contains a vulnerability related to insufficient data integrity verification.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2023-4929 // JVNDB: JVNDB-2023-013859

AFFECTED PRODUCTS

vendor:moxamodel:nport 5250ai-m12scope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150i-s-scscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia-5150i-m-sc-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia5250ai-t-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5232-tscope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport ia5450aiscope:lteversion:2.0

Trust: 1.0

vendor:moxamodel:nport 5410scope:gteversion:3.2

Trust: 1.0

vendor:moxamodel:nport ia-5150i-s-scscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150i-m-sc-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150i-s-sc-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5430scope:gteversion:3.2

Trust: 1.0

vendor:moxamodel:nport 5610-16-48vscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5650-16-s-scscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5150ai-m12-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5230scope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport ia-5150i-s-sc-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5150ai-m12scope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5250iscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150-s-scscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5230a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5650-16-m-scscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-stscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5250ai-m12-ctscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5650-16-tscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia-5150-s-scscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5150ai-m12-ct-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5130a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport ia-5150iscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia5150a-t-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5250scope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5110-tscope:lteversion:2.10

Trust: 1.0

vendor:moxamodel:nport ia5150ai-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150iscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5210scope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5650-8-dtscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport ia-5250scope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia5450a-tscope:lteversion:2.0

Trust: 1.0

vendor:moxamodel:nport ia5250ascope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5450i-tscope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport 5150a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5610-16scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia5450ai-tscope:lteversion:2.0

Trust: 1.0

vendor:moxamodel:nport 5110ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport ia5150aiscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5250a-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5000a-i\/oscope:lteversion:2.0

Trust: 1.0

vendor:moxamodel:nport ia-5150scope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia5250aiscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5150ascope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5150ai-t-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5150a-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150i-m-scscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5610-8-dt-tscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport 5650i-8-dt-tscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport ia5250ai-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5630-16scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5410scope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-st-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-scscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5150scope:lteversion:3.10

Trust: 1.0

vendor:moxamodel:nport 5450ai-m12scope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia5250ai-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5430scope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport iaw5000a-i\/oscope:lteversion:2.2

Trust: 1.0

vendor:moxamodel:nport p5150ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5130ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-scscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5650-8-s-scscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5450ai-m12-ct-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5210ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5610-8-dtscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport 5232i-tscope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5650-8scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia5150ai-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5450-tscope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport 5410scope:gteversion:2.0

Trust: 1.0

vendor:moxamodel:nport 5650-8-dt-tscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport ia-5250iscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5210a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5610-8-dt-jscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport 5430scope:gteversion:2.0

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-stscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5232scope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5232iscope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5650-8-tscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5410scope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport ia5250a-t-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5650-16scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5650-8-m-scscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5250ai-m12-ct-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5610-8scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5430scope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport ia5150a-iexscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5650-16-hv-tscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia-5150i-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia5450ascope:lteversion:2.0

Trust: 1.0

vendor:moxamodel:nport 5210-tscope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5610-8-48vscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia-5250i-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5150ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport ia-5150-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia-5150i-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5130scope:lteversion:3.10

Trust: 1.0

vendor:moxamodel:nport 5650i-8-dtscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport 5110a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport ia-5250i-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150scope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5650-8-hv-tscope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport 5450ai-m12-ctscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150i-m-scscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5230-tscope:lteversion:2.12

Trust: 1.0

vendor:moxamodel:nport 5450iscope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport 5630-8scope:lteversion:3.11

Trust: 1.0

vendor:moxamodel:nport ia-5150-s-sc-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5150ai-m12-ctscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5250-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport 5650-8-dt-jscope:lteversion:2.9

Trust: 1.0

vendor:moxamodel:nport 5450ai-m12-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150-s-sc-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-st-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-sc-tscope:lteversion:2.1

Trust: 1.0

vendor:moxamodel:nport ia-5250-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport 5250ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport p5150a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5250ai-m12-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport ia-5150-m-sc-tscope:lteversion:1.7

Trust: 1.0

vendor:moxamodel:nport ia5250a-tscope:lteversion:1.5

Trust: 1.0

vendor:moxamodel:nport 5450scope:lteversion:3.14

Trust: 1.0

vendor:moxamodel:nport 5250a-tscope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5230ascope:lteversion:1.6

Trust: 1.0

vendor:moxamodel:nport 5110scope:lteversion:2.10

Trust: 1.0

vendor:moxamodel:nport 5150ai-m12-ct-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5250ai-m12-ctscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5450ai-m12-ct-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5110-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5250ai-m12-ct-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5450ai-m12-ctscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5130ascope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5110a-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5110ascope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5110scope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5150ai-m12-ctscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5130a-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5450ai-m12scope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5130scope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5150scope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5250ai-m12scope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5150ai-m12-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5250ai-m12-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5450ai-m12-tscope: - version: -

Trust: 0.8

vendor:moxamodel:nport 5150ai-m12scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859 // NVD: CVE-2023-4929

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-4929
value: HIGH

Trust: 1.0

psirt@moxa.com: CVE-2023-4929
value: MEDIUM

Trust: 1.0

NVD: CVE-2023-4929
value: HIGH

Trust: 0.8

nvd@nist.gov: CVE-2023-4929
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

psirt@moxa.com: CVE-2023-4929
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.2
version: 3.1

Trust: 1.0

NVD: CVE-2023-4929
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859 // NVD: CVE-2023-4929 // NVD: CVE-2023-4929

PROBLEMTYPE DATA

problemtype:CWE-354

Trust: 1.0

problemtype:Incomplete data integrity verification (CWE-354) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859 // NVD: CVE-2023-4929

EXTERNAL IDS

db:NVDid:CVE-2023-4929

Trust: 2.6

db:JVNDBid:JVNDB-2023-013859

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859 // NVD: CVE-2023-4929

REFERENCES

url:https://www.moxa.com/en/support/product-support/security-advisory/mpsa-233328-nport-5000-series-firmware-improper-validation-of-integrity-check-vulnerability

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2023-4929

Trust: 0.8

sources: JVNDB: JVNDB-2023-013859 // NVD: CVE-2023-4929

SOURCES

db:JVNDBid:JVNDB-2023-013859
db:NVDid:CVE-2023-4929

LAST UPDATE DATE

2024-08-14T15:00:02.463000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2023-013859date:2023-12-22T02:33:00
db:NVDid:CVE-2023-4929date:2023-10-06T15:28:35.260

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2023-013859date:2023-12-22T00:00:00
db:NVDid:CVE-2023-4929date:2023-10-03T14:15:11.307