CVE-2024-12297
published 2025-01-15CVE-2024-12297: Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server…
PriorityP260critical9.2CVSS 4.0
AVNACLATPPRNUINVCHVIHVAHSCLSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.82%
52.9th percentile
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | eds-508a_series | 1.0 – 3.11 | — |
| moxa | pt-508_series | 1.0 – 3.8 | — |
| moxa | pt-510_series | 1.0 – 3.8 | — |
| moxa | pt-7528_series | 1.0 – 5.0 | — |
| moxa | pt-7728_series | 1.0 – 3.9 | — |
| moxa | pt-7828_series | 1.0 – 4.0 | — |
| moxa | pt-g503_series | 1.0 – 5.3 | — |
| moxa | pt-g510_series | 1.0 – 6.5 | — |
| moxa | pt-g7728_series | 1.0 – 6.5 | — |
| moxa | pt-g7828_series | 1.0 – 6.5 | — |
CVSS provenance
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp78-8mxr-44qr: Moxa’s Ethernet switch EDS-508A Series, running firmware version 3
ghsa_unreviewed·2025-01-15
CVE-2024-12297 [CRITICAL] CWE-656 GHSA-jp78-8mxr-44qr: Moxa’s Ethernet switch EDS-508A Series, running firmware version 3
Moxa’s Ethernet switch EDS-508A Series, running firmware version 3.11 and earlier, is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.
Red Hat
kernel: wifi: ath12k: Skip Rx TID cleanup for self peer
vendor_redhat·2024-12-27·CVSS 5.5
CVE-2024-56543 [MEDIUM] kernel: wifi: ath12k: Skip Rx TID cleanup for self peer
kernel: wifi: ath12k: Skip Rx TID cleanup for self peer
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Skip Rx TID cleanup for self peer
During peer create, dp setup for the peer is done where Rx TID is
updated for all the TIDs. Peer object for self peer will not go through
dp setup.
When core halts, dp cleanup is done for all the peers. While cleanup,
rx_tid::ab is accessed which causes below stack trace for self peer.
WARNING: CPU: 6 PID: 12297 at drivers/net/wireless/ath/ath12k/dp_rx.c:851
Call Trace:
__warn+0x7b/0x1a0
ath12k_dp_rx_frags_cleanup+0xd2/0xe0 [ath12k]
report_bug+0x10b/0x200
handle_bug+0x3f/0x70
exc_invalid_op+0x13/0x60
asm_exc_invalid_op+0x16/0x20
ath12k_dp_rx_frags_cleanup+0xd2/0xe0 [ath12k]
ath12k_dp_rx_frags_cleanup+0xca/0xe0 [ath12k]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241407-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-in-eds-508a-serieshttps://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches
2025-01-15
Published