VulnerabilityModified
CVE-2023-4929
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability.
HIGH 8.8EPSS 0.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.26% probability · 18th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-354
- Affected
- moxa/nport 5150ai-m12-ct-t firmware · moxa/nport 5250ai-m12-ct-t firmware · moxa/nport 5150ai-m12-t firmware · moxa/nport 5250ai-m12-t firmware · moxa/nport 5450ai-m12-ct-t firmware · moxa/nport 5150ai-m12 firmware · moxa/nport 5250ai-m12 firmware · moxa/nport 5150ai-m12-ct firmware · moxa/nport 5250ai-m12-ct firmware · moxa/nport 5450ai-m12-t firmware · moxa/nport 5450ai-m12 firmware · moxa/nport 5450ai-m12-ct firmware · moxa/nport 5130 firmware · moxa/nport 5150 firmware · moxa/nport 5110 firmware · moxa/nport 5110-t firmware · moxa/nport 5110a firmware · moxa/nport 5110a-t firmware · moxa/nport 5130a firmware · moxa/nport 5130a-t firmware · +40 more
- Source
- psirt@moxa.com
References
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-233328-nport-5000-series-firmware-improper-validation-of-integrity-check-vulnerabilityVendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-233328-nport-5000-series-firmware-improper-validation-of-integrity-check-vulnerabilityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.