Product support

Security Advisories

SUMMARY

MiiNePort E1/E2/E3 Series Serial Device Server Vulnerabilities

  • Version: 1.0
  • Release Date: Jul 01, 2016
  • Reference:

Multiple product vulnerabilities were identified in Moxa’s E1/E2/E3 Series Serial Device Server. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Clear text storage of sensitive information Disclosure of sensitive information
2 Cross-site request forgery Unverified HTTP requests may allow atacker to trick user into making unintentional request
3 Weak credential management Authentication bypass for administration

 

AFFECTED PRODUCTS AND SOLUTIONS

Affected Products

The affected products and firmware versions are shown below.

Product Series Affected Version
MiiNePort E1 Series Firmware Version 1.7 or prior
MiiNePort E2 Series Firmware Version 1.3 or prior
MiiNePort E3 Series Firmware Version 1.0 or prior

 

Solutions

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
MiiNePort E1 Series Please download the new firmware/software here.
MiiNePort E2 Series Please download the new firmware/software here.
MiiNePort E3 Series Please download the new firmware/software here.

 

Revision History

Version Description Release Date
1.0 First Release Jul 1, 2016

 

Relevant Products

MiiNePort E1 Series · MiiNePort E2 Series · MiiNePort E3 Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s Get That Fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag