Home Cyber Security News Moxa Switches Vulnerability Allows Attackers to Bypass Authentication

Moxa Switches Vulnerability Allows Attackers to Bypass Authentication

0
Moxa Switches Vulnerability Allows Attackers to Bypass Authentication

Moxa has issued a critical security advisory (MPSA-241409, Version 1.0) addressing a severe vulnerability in multiple industrial Ethernet switches that could allow attackers to bypass authentication controls.

The flaw, tracked as CVE-2024-12297, was publicly disclosed on February 4, 2026, and carries a CVSS 4.0 base score of 9.2 (Critical).

Vulnerability Overview

This vulnerability, titled “Frontend Authorization Logic Disclosure,” affects Moxa’s TN-A and TN-G Ethernet switch series.

It stems from weaknesses in the device’s authentication mechanism, specifically, improper coordination between client-side and back-end authorization logic.

Attackers exploiting this flaw could perform brute-force attacks to guess valid credentials or use MD5 hash collision techniques to forge authentication signatures.

Successful exploitation could allow remote attackers to gain unauthorized access to switch management interfaces, potentially enabling lateral movement or configuration tampering within the operational network.

Moxa identified the root cause as reliance on obscured authentication logic rather than securely enforced server-side validation.

Technical Classification

IDVulnerability TitleType (CWE)Attack Pattern (CAPEC)CVSS 4.0 Base ScoreVectorAuthentication RequiredRemote Exploitable
CVE-2024-12297Frontend Authorization Logic DisclosureCWE-656: Reliance on Security Through ObscurityCAPEC-49: Password Brute Forcing9.2 (Critical)AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:LNoYes

Affected Products and Solutions

Moxa confirmed that multiple versions of its industrial-grade switches are impacted. The company released patched firmware to address the issue. Affected products include:

Product SeriesAffected VersionsSolution
TN-A Series / TN-4500A / TN-5500AFirmware v4.1 and earlierApply patch version v3.13.255 – available via Moxa Technical Support
TN-G Series / TN-G4500 / TN-G6500Firmware v5.5 and earlierApply patch version v5.5.255 – available via Moxa Technical Support

Administrators unable to immediately upgrade firmware are advised to employ the following mitigations:

  • Restrict network access to trusted administrative hosts.
  • Enable network segmentation to limit switch management traffic.
  • Regularly audit logs for suspicious login attempts or hash anomalies.
  • Follow Moxa’s General Security Recommendations to strengthen device security posture.

Given the vulnerability’s high potential impact on industrial communication networks, organizations using Moxa switches should prioritize patch deployment and verify that authentication mechanisms are functioning correctly post-update.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here