Product support

Security Advisories

SUMMARY

NPort 5000 Series, and NPort 6000 Series Serial Device Server Vulnerabilities

Multiple product vulnerabilities were identified in Moxa’s NPort 5000 Series, and NPort 6000 Series Serial Device Server. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Unauthenticated retrievable sensitive account information Ensure that passwords have been enabled.
2 Unauthenticated remote firmware update Ensure that passwords have been enabled.
3 Buffer overflow Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability.
4 Cross-site scription Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability.
5 Cross-site request forgery Setup access control to devices to prevent any un-authorized access from those taking advantage of the vulnerability.

 

AFFECTED PRODUCTS AND SOLUTIONS

Affected Products

The affected products and firmware versions are shown below.

Product Series Affected Version
NPort 5100 Series (NPort 5110 / NPort 5110-T) Firmware Version 2.5 or prior
NPort 5100 Series (NPort 5130 / NPort 5150) Firmware Version 3.5 or prior
NPort 5200 Series Firmware Version 2.7 or prior
NPort 5400 Series Firmware Version 3.10 or prior
NPort 5600 Series Firmware Version 3.6 or prior
NPort 5600-DT Series Firmware Version 2.3 or prior
NPort 5600-DTL Series Firmware Version 1.2 or prior
NPort 5100A Series Firmware Version 1.2 or prior
NPort 5200A Series Firmware Version 1.2 or prior
NPort P5150A Series Firmware Version 1.2 or prior
NPort 5000AI-M12 Series Firmware Version 1.1 or prior
NPort 6100/6200 Series Firmware Version 1.13 or prior
NPort 6400/6600 Series Firmware Version 1.13 or prior
NPort 6110 Series Firmware Version 1.13 or prior

 

Solutions

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for the affected products are shown below.

Product Series Solutions
NPort 5100 Series (NPort 5110 / NPort 5110-T) Please download the new firmware/software here.
NPort 5100 Series (NPort 5130 / NPort 5150) Please download the new firmware/software here.
NPort 5200 Series Please download the new firmware/software here.
NPort 5400 Series Please download the new firmware/software here.
NPort 5600 Series Please download the new firmware/software here.
NPort 5600-DT Series Please download the new firmware/software here.
NPort 5600-DTL Series Please download the new firmware/software here.
NPort 5100A Series Please download the new firmware/software here.
NPort 5200A Series Please download the new firmware/software here.
NPort P5150A Series Please download the new firmware/software here.
NPort 5000AI-M12 Series Please download the new firmware/software here.
NPort 6100/6200 Series Please download the new firmware/software here.
NPort 6400/6600 Series Please download the new firmware/software here.
NPort 6110 Series This product has been phased out. Please contact Moxa Technical Support for assistance.

 

Revision History

 

Version Description Release Date
1.0 First Release Apr 15, 2016

Relevant Products

NPort 5000AI-M12 Series · NPort 5100 Series · NPort 5100A Series · NPort 5200 Series · NPort 5200A Series · NPort 5400 Series · NPort 5600 Series · NPort 5600-DT Series · NPort 5600-DTL Series · NPort 6100/6200 Series · NPort P5150A Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag