cvelist/2024/9xxx/CVE-2024-9139.json

205 lines
10 KiB
JSON
Raw Normal View History

2024-09-24 08:00:35 +00:00
{
2024-10-14 09:00:35 +00:00
"data_version": "4.0",
2024-09-24 08:00:35 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-9139",
2024-10-14 09:00:35 +00:00
"ASSIGNER": "psirt@moxa.com",
"STATE": "PUBLIC"
2024-09-24 08:00:35 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2024-10-14 09:00:35 +00:00
"value": "The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
"cweId": "CWE-78"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Moxa",
"product": {
"product_data": [
{
"product_name": "EDR-8010 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.12.1"
}
]
}
},
{
"product_name": "EDR-G9004 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.12.1"
}
]
}
},
{
"product_name": "EDR-G9010 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.12.1"
}
]
}
},
{
"product_name": "EDF-G1002-BP Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.12.1"
}
]
}
},
{
"product_name": "NAT-102 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "1.0.5"
}
]
}
},
{
"product_name": "OnCell G4302-LTE4 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.9"
}
]
}
},
{
"product_name": "TN-4900 Series",
"version": {
"version_data": [
{
2024-10-15 08:00:33 +00:00
"version_affected": "<=",
"version_name": "1.0",
2024-10-14 09:00:35 +00:00
"version_value": "3.6"
}
]
}
2024-10-25 07:00:37 +00:00
},
{
"product_name": "EDR-810 Series",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "1.0",
"version_value": "5.12.33"
}
]
}
2024-10-14 09:00:35 +00:00
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241154-missing-authentication-and-os-command-injection-vulnerabilities-in-routers-and-network-security-appliances",
"refsource": "MISC",
"name": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241154-missing-authentication-and-os-command-injection-vulnerabilities-in-routers-and-network-security-appliances"
}
]
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"discovery": "EXTERNAL"
},
"work_around": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
2024-10-15 08:00:33 +00:00
"value": "<p></p><ul><li>Minimize network exposure to ensure the device is not accessible from the Internet.</li><li>Limit web access to trusted IP addresses and networks by using firewall rules or TCP wrappers.</li><li>Implement IDS or Intrusion Prevention System (IPS) to detect and prevent exploitation attempts. These systems can provide an additional layer of defense by monitoring network traffic for signs of attacks.</li></ul><p></p>\n\n\n<br>"
2024-10-14 09:00:35 +00:00
}
],
2024-10-15 08:00:33 +00:00
"value": "* Minimize network exposure to ensure the device is not accessible from the Internet.\n * Limit web access to trusted IP addresses and networks by using firewall rules or TCP wrappers.\n * Implement IDS or Intrusion Prevention System (IPS) to detect and prevent exploitation attempts. These systems can provide an additional layer of defense by monitoring network traffic for signs of attacks."
2024-10-14 09:00:35 +00:00
}
],
"solution": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
2024-10-25 07:00:37 +00:00
"value": "<p>Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for the affected products are shown below.</p><ol><li><span style=\"background-color: var(--wht);\">EDR-8010 Series: Upgrade to the firmware version 3.13 or later version.</span></li><li>EDR-G9004 Series: Upgrade to the firmware version 3.13 or later version.</li><li>EDR-G9010 Series: Upgrade to the firmware version 3.13 or later version.</li><li>EDF-G1002-BP Series: Upgrade to the firmware version 3.13 or later version.</li><li>NAT-102 Series: Please contact Moxa Technical Support for the security patch.</li><li>OnCell G4302-LTE4 Series: Upgrade to the firmware version 3.13 or later version.</li><li>TN-4900 Series: Upgrade to the firmware version 3.13 or later version.</li><li>EDR-810 Series: Upgrade to the firmware version 5.12.37 or later version.</li></ol><br>"
2024-10-14 09:00:35 +00:00
}
],
2024-10-25 07:00:37 +00:00
"value": "Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for the affected products are shown below.\n\n * EDR-8010 Series: Upgrade to the firmware version 3.13 or later version.\n * EDR-G9004 Series: Upgrade to the firmware version 3.13 or later version.\n * EDR-G9010 Series: Upgrade to the firmware version 3.13 or later version.\n * EDF-G1002-BP Series: Upgrade to the firmware version 3.13 or later version.\n * NAT-102 Series: Please contact Moxa Technical Support for the security patch.\n * OnCell G4302-LTE4 Series: Upgrade to the firmware version 3.13 or later version.\n * TN-4900 Series: Upgrade to the firmware version 3.13 or later version.\n * EDR-810 Series: Upgrade to the firmware version 5.12.37 or later version."
2024-10-14 09:00:35 +00:00
}
],
"credits": [
{
"lang": "en",
"value": "Lars Haulin"
}
],
"impact": {
"cvss": [
{
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
2024-09-24 08:00:35 +00:00
}
]
}
}