CRITICAL
Moxa MiiNePort E1 - Broken Access Control
Published Apr 27, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.89%
Description
Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.
Affected products
-
- Version 1.7.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Moxa | MiiNePort E1 | n/a |
|
AND
- 1.7.2
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update MiiNePort E1 version to 1.8
Weaknesses (1)
References (3)
- https://cdn-cms.azureedge.net/Moxa/media/PDIM/S100000223/MiiNePort%20E1%20Series_moxa-miineport-e1-series-firmware-v1.9.rom_Software%20Release%20History.pdf Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-32340 Advisory
- https://www.twcert.org.tw/tw/cp-132-7021-eb43a-1.html Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Apr 27, 2023
Updated Jan 31, 2025
Reserved Mar 21, 2023
Link CVE-2023-28697
CISA Vulnrichment
Updated Jan 31, 2025
ENISA EUVD
EUVD-2023-32340 Assigner twcert
Published Apr 27, 2023
Updated Jan 31, 2025
Exploited since n/a
Link EUVD-2023-32340