Privilege Escalation in Cellular Router, Secure Router, and Network Security Appliances
Published Jan 3, 2025
8.6
HIGHCVSS 4.0
EPSS 1.16%
Description
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an authenticated user to escalate privileges and gain root-level access to the system, posing a significant security risk.
Affected products
-
- Version 1.0StatusaffectedConstraints<=3.13.1
- Version
-
- Version 1.0StatusaffectedConstraints<=3.13.1
- Version
-
- Version 1.0StatusaffectedConstraints<=5.12.37
- Version
-
- Version 1.0StatusaffectedConstraints<=3.13.1
- Version
-
- Version 1.0StatusaffectedConstraints<=3.13.1
- Version
-
- Version 1.0StatusaffectedConstraints<=5.7.25
- Version
-
- Version 1.0StatusaffectedConstraints<=5.7.25
- Version
-
- Version 1.0StatusaffectedConstraints<=1.0.5
- Version
-
- Version 1.0StatusaffectedConstraints<=3.13
- Version
-
- Version 1.0StatusaffectedConstraints<=3.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Moxa | EDF-G1002-BP Series | unaffected |
| ||||||
| Moxa | EDR-8010 Series | unaffected |
| ||||||
| Moxa | EDR-810 Series | unaffected |
| ||||||
| Moxa | EDR-G9004 Series | unaffected |
| ||||||
| Moxa | EDR-G9010 Series | unaffected |
| ||||||
| Moxa | EDR-G902 Series | unaffected |
| ||||||
| Moxa | EDR-G903 Series | unaffected |
| ||||||
| Moxa | NAT-102 Series | unaffected |
| ||||||
| Moxa | OnCell G4302-LTE4 Series | unaffected |
| ||||||
| Moxa | TN-4900 Series | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Moxa has developed appropriate solutions to address vulnerability. The solutions for the affected products are listed below.
* EDR-810 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-810-series#resources or later * EDR-8010 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-8010-series#resources or later * EDR-G902 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g902-series#resources or later * EDR-G903 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g903-series#resources or later * EDR-G9004 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g9004-series#resources or later * EDR-G9010 Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/secure-routers/secure-routers/edr-g9010-series#resources or later * EDF-G1002-BP Series: Upgrade to the firmware version 3.14 https://www.moxa.com/en/products/industrial-network-infrastructure/network-security-appliance/edf-g1002-bp-series#resources or later * NAT-102 Series: An official patch or firmware update is not currently available for this product. Please refer to the Mitigations section below for recommended measures to address the vulnerability. * OnCell G4302-LTE4 Series: Please contact Moxa Technical Support https://www.moxa.com/support/support/technical-support for the security patch * TN-4900 Series: Please contact Moxa Technical Support https://www.moxa.com/support/support/technical-support for the security patch
References (2)
Change history (0)
No recorded changes yet.