BDU:2023-02362Critical
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Share link
Anyone with the link can open this vulnerability.
Уязвимость микропрограммного обеспечения асинхронных серверов Moxa NPort связана с недостатками процедуры аутентификации. Эксплуатация уязв…
CVSS
9.8
Critical
EPSS
0.00
p0
Published
2023-01-01
Updated
2023-01-01
Description
Уязвимость микропрограммного обеспечения асинхронных серверов Moxa NPort связана с недостатками процедуры аутентификации. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, выполнить произвольный код
Tags · CWE
Pre-auth
Affected products
Moxa inc. Nport 5100aMoxa inc. Nport 5110Moxa inc. Nport 5130/5150Moxa inc. Nport 5150ai-m12Moxa inc. Nport 5200Moxa inc. Nport 5200aMoxa inc. Nport 5250ai-m12Moxa inc. Nport 5400Moxa inc. Nport 5450ai-m12Moxa inc. Nport 5600Moxa inc. Nport 5600-8-dtMoxa inc. Nport 5600-8-dtlMoxa inc. Nport 6000Moxa inc. Nport 6110Moxa inc. Nport ia5450aMoxa inc. Nport p5150a
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
| Product | Vendor | Status |
|---|---|---|
| nport 5100a | moxa inc. | Tracked |
| nport 5110 | moxa inc. | Tracked |
| nport 5130/5150 | moxa inc. | Tracked |
| nport 5150ai-m12 | moxa inc. | Tracked |
| nport 5200 | moxa inc. | Tracked |
| nport 5200a | moxa inc. | Tracked |
| nport 5250ai-m12 | moxa inc. | Tracked |
| nport 5400 | moxa inc. | Tracked |
| nport 5450ai-m12 | moxa inc. | Tracked |
| nport 5600 | moxa inc. | Tracked |
| nport 5600-8-dt | moxa inc. | Tracked |
| nport 5600-8-dtl | moxa inc. | Tracked |
| nport 6000 | moxa inc. | Tracked |
| nport 6110 | moxa inc. | Tracked |
| nport ia5450a | moxa inc. | Tracked |
| nport p5150a | moxa inc. | Tracked |
Source databases
BDU
BDU
Data Bank of Information Security Threats
BDU ФСТЭК is the authoritative Russian source of vulnerability information, covering both international CVEs relevant to domestic software and unique Russian-disclosed issues. Entries contain severity, affected product lists (in Russian), and mitigation recommendations.
Region
RU
Updates
1 ч
License
Открытые данные
Russian federal catalog of vulnerabilities and threats maintained by FSTEC. Required for compliance with Russian information security regulations (Приказ №17, Приказ №21).
https://bdu.fstec.ru →Related vulnerabilities