当前位置:网站首页>Moxa NPort device flaw could expose critical infrastructure to devastating attack
Moxa NPort device flaw could expose critical infrastructure to devastating attack
2022-07-31 02:46:00 【Network Research Institute】
Two potentially critical vulnerabilities that could allow threat actors to wreak havoc have been discovered in widely used industrial connected devices manufactured by Moxa.
The Taiwan-based provider of industrial networking and automation solutions has addressed these deficiencies.
The two security vulnerabilities, tracked as CVE-2022-2043 and CVE-2022-2044, rated "High Severity", affect Moxa's NPort 5110 device server, which is designed to connect serial devices toto the Ethernet network.A remote attacker could exploit these vulnerabilities to put a target device into a Denial of Service (DoS) state.
Moxa and the U.S. Cybersecurity and Infrastructure Security Agency ( CISA ) have issued advisories for these vulnerabilities.Moxa said only firmware version 2.10 was affected, and instructed customers to contact their technical support for assistance.CISA asked affected organizations to contact Moxa for security patches.
Moxa and CISA both praised Jens Nielsen, a researcher at Danish industrial cybersecurity firm En Garde Security, for reporting the vulnerabilities.
In a blog post published this week, En Garde Security owner Mikael Vingaard said his company's research department discovered the vulnerabilities in the first half of March 2022, when a proof-of-concept (PoC) was made available to the vendor.) script and a video showing the exploit.
Vingaard told us that while Moxa NPort devices should not be exposed to the Internet, many devices are actually accessible over the network.A Shodan search revealed over 5,000 devices, and while there may be some honeypots, they can't all be honeypots.
He said that exploiting the two flaws only requires a network connection to the target device.Exploits can be executed "in seconds" and can be automated over the internet.
Affected NPort devices are used worldwide, including in critical infrastructure sectors such as energy, critical manufacturing and transportation systems.There were reports that these types of equipment were targeted for sabotage in an attack on Ukraine's power grid in 2015, causing severe power outages.
Exploiting the vulnerabilities discovered by En Garde researchers could disrupt critical services in these sectors, Vingaard described vulnerable Moxa devices as "a small fraction of our society's vital infrastructure services."
He explained that the first DoS vulnerability could allow an attacker to make a target device stop responding to legitimate commands.
“The only way to regain control of the equipment is to have staff power off/on the equipment, which requires someone to be physically present,” “This can often cause problems in remote areas where it can take a significant amount of time to get people on site, andNot ideal in situations where time to regain control may be important."
The second vulnerability is an out-of-bounds issue where an attacker can access and/or overwrite elements on the device, resulting in data corruption or corruption.This renders the system inoperable and in some cases may cause permanent damage to the device.
边栏推荐
- Go 项目实战-获取多级分类下的全部商品
- The simulation application of common mode inductance is here, full of dry goods for everyone
- Static routing + PAT + static NAT (explanation + experiment)
- 图像处理技术的心酸史
- Observer mode (1)
- Mathematics to solve the problem - circular linked list
- 【C语言】求两个整数m和n的最大公因数和最小公倍数之和一般方法,经典解法
- TCP/IP four-layer model
- How to design the changing system requirements
- 2022牛客多校联赛第四场 题解
猜你喜欢
分布式与集群是什么 ? 区别是什么?
【C语言】求两个整数m和n的最大公因数和最小公倍数之和一般方法,经典解法
The application of AI in the whole process of medical imaging equipment
MPPT solar charge controller data collection - through the gateway acquisition capacity battery SOC battery voltage, wi-fi
STM32CUBEMX develops GD32F303 (11) ---- ADC scans multiple channels in DMA mode
10 权限介绍
f.grid_sample
Static route analysis (the longest mask matching principle + active and standby routes)
6、显示评论和回复
10. Redis implements likes (Set) and obtains the total number of likes
随机推荐
【C语言】求两个整数m和n的最大公因数和最小公倍数之和一般方法,经典解法
19.支持向量机-优化目标和大间距直观理解
自动化办公案例:如何自动生成期数据?
Inter-vlan routing + static routing + NAT (PAT + static NAT) comprehensive experiment
AI中的数学思想
Project (5) - Small target detection tph-yolov5
Real-time image acquisition based on FPGA
Maximum area of solar panel od js
JS 函数 this上下文 运行时点语法 圆括号 数组 IIFE 定时器 延时器 self.备份上下文 call apply
冒泡排序、选择排序、直接插入排序、二分法查找
16、热帖排行
Discussion on Service Commitment of Class Objects under Multithreading
【C语言】进制转换一般方法
CentOS7下mysql5.7.37的卸载【完美方案】
开题报告之论文框架
Refuse to work overtime, a productivity tool set developed by programmers
Teach you how to configure Jenkins automated email notifications
TCP/IP four-layer model
YOLOV5 study notes (3) - detailed explanation of network module
Pythagorean tuple od js