Eight Vulnerabilities Found in Moxa NPort Devices

  • 2 December 2016
  • 0 replies
  • 86 views

Userlevel 7
Badge +54
By Eduard Kovacs on December 02, 2016 Security researchers have discovered a total of eight vulnerabilities in NPort serial device servers produced by Taiwan-based industrial automation solutions provider Moxa, ICS-CERT reported on Thursday.

The flaws discovered by Reid Wightman, Mikael Vingaard and Maxim Rupp affect more than a dozen NPort models.

Three of the security holes have a CVSS score of 9.8, which puts them in the critical severity category. They can be exploited to retrieve an administrator password without authentication, update the device’s firmware over the network without authentication and potentially achieve code execution, and use brute force to bypass authentication. Full Article

0 replies

Be the first to reply!

Reply