As of June 15, 2022, this site no longer supports Internet Explorer. Please use another browser for the best experience on our site.

Product support

Security Advisories

SUMMARY

NPort IAW5000A-I/O Series Serial Device Servers Vulnerabilities

  • Security Advisory ID: MPSA-211102
  • Version: V1.0
  • Release Date: Nov 23, 2021
  • Reference:
    • BDU:2021-05559, BDU:2021-05560, BDU:2021-05561

Multiple product vulnerabilities were identified in Moxa’s NPort IAW5000A-I/O Series Servers. In response to this, Moxa has developed related solutions to address these vulnerabilities..

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Use of a Hard-coded Cryptographic Key in Firmware (CWE-321), Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
BDU:2021-05559
Malicious users can gain access through a hard-coded password.
2 Use of Hard-coded Cryptographic Key in Program Module (CWE-321)
BDU:2021-05560
The possibility of malicious users encrypting sensitive data through a hard-coded cryptographic key is increased.
3 Use of Platform-dependent Third-party Components With vulnerabilities (CWE-1103)
BDU:2021-05561
An outdated webserver component may have unfixed vulnerabilities.
AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
NPort IAW5000A-I/O Series Firmware Version 1.2 or lower.

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
NPort IAW5000A-I/O Series Items 1 and 2: The old firmware v1.2 is not available to download from moxa.com. And for security reasons, we strongly recommend that you only download firmware v2.2 (Download Link) or higher from moxa.com directly or other trusted sources.

Item 3: Please upgrade to firmware version 2.2 or higher. (Download Link)

Acknowledgment:

We would like to express our appreciation to Ilya Karpov, Konstantin Kondratev, and Evgeniy Druzhinin of Rostelecom-Solar for reporting the vulnerability, working with us to help enhance the security of our products, and helping us provide a better service to our customers.
 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Nov 23, 2021

Relevant Products

NPort IAW5000A-I/O Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag
You have some items waiting in your bag; click here to finish your quote!
Feedback