SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-4929

All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability.

HIGH 8.8EPSS 0.26%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.26% probability · 18th percentile
CISA KEV
Not listed
Weakness
CWE-354
Affected
moxa/nport 5150ai-m12-ct-t firmware · moxa/nport 5250ai-m12-ct-t firmware · moxa/nport 5150ai-m12-t firmware · moxa/nport 5250ai-m12-t firmware · moxa/nport 5450ai-m12-ct-t firmware · moxa/nport 5150ai-m12 firmware · moxa/nport 5250ai-m12 firmware · moxa/nport 5150ai-m12-ct firmware · moxa/nport 5250ai-m12-ct firmware · moxa/nport 5450ai-m12-t firmware · moxa/nport 5450ai-m12 firmware · moxa/nport 5450ai-m12-ct firmware · moxa/nport 5130 firmware · moxa/nport 5150 firmware · moxa/nport 5110 firmware · moxa/nport 5110-t firmware · moxa/nport 5110a firmware · moxa/nport 5110a-t firmware · moxa/nport 5130a firmware · moxa/nport 5130a-t firmware · +40 more
Source
psirt@moxa.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.