CVE-2023-1257
published 2023-03-07CVE-2023-1257: An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options…
PriorityP432medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.32%
23.5th percentile
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | uc-2100-w_series | — | — |
| moxa | uc-2100_series | — | — |
| moxa | uc-2101-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2102-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2102-t-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2104-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2111-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2112-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2114-t-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-2116-t-lx_firmware | 1.3 – 1.5 | — |
| moxa | uc-3100_series | — | — |
| moxa | uc-3101-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3101-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3101-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-ap-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-eu-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-us-lx-nw_firmware | 1.2 – 2.0 | — |
| moxa | uc-3111-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-ap-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-eu-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-3121-t-us-lx_firmware | 1.2 – 2.0 | — |
| moxa | uc-5100_series | — | — |
| moxa | uc-5101-lx_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa UC Series (Update A)
cisa_ics·2022-11-29·CVSS 7.6
[HIGH] Moxa UC Series (Update A)
ICS Advisory
##
Moxa UC Series (Update A)
Last RevisedFebruary 23, 2023
Alert CodeICSA-22-333-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.6
- ATTENTION: Low attack complexity
- Vendor: Moxa
- Equipment: UC Series
- Vulnerability: Improper Physical Access Control
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-22-333-04 Moxa UC Series that was published November 29, 2022 on the ICS webpage on cisa.gov/ICS.
## 3. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker with physical access to take full control of the device using the console port.
## 4. TECHNICAL DETAILS
## 4.1 AFFECTED PRODUCTS
The following bootloader versions of Moxa UC Series, industrial internet-of-things (II
GHSA
GHSA-whp2-gjjf-pvgr: An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS
ghsa_unreviewed·2023-07-06
CVE-2023-1257 [MEDIUM] CWE-1263 GHSA-whp2-gjjf-pvgr: An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS
An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-07
Published