{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2023-4929", "ASSIGNER": "psirt@moxa.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.\n\n" } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-354 Improper Validation of Integrity Check Value", "cweId": "CWE-354" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Moxa", "product": { "product_data": [ { "product_name": "NPort 5000AI-M12 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "1.5" } ] } }, { "product_name": "NPort 5100 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "3.10" } ] } }, { "product_name": "NPort 5100A Series ", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "1.6" } ] } }, { "product_name": "NPort 5200 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.12" } ] } }, { "product_name": "NPort 5200A Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "1.6" } ] } }, { "product_name": "NPort 5400 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "3.14" } ] } }, { "product_name": "NPort 5600 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "3.11" } ] } }, { "product_name": "NPort 5600-DT Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.9" } ] } }, { "product_name": "NPort IA5000 Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.1" } ] } }, { "product_name": "NPort IA5000A Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.0" } ] } }, { "product_name": "NPort IA5000A-I/O Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.0" } ] } }, { "product_name": "NPort IAW5000A-I/O Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "2.2" } ] } }, { "product_name": "NPort P5150A Series", "version": { "version_data": [ { "version_affected": "<=", "version_name": "1.0", "version_value": "1.6" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-233328-nport-5000-series-firmware-improper-validation-of-integrity-check-vulnerability", "refsource": "MISC", "name": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-233328-nport-5000-series-firmware-improper-validation-of-integrity-check-vulnerability" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "solution": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Due to design restrictions, we could not fix this vulnerability in NPort 5000 Series. We suggest users follow the instructions in the hardening guide in order to mitigate this vulnerability. Additionally, refer to the following mitigation measures to deploy the product in an appropriate product security context.
Moxa recommends users follow these CISA recommendations. Users should