As of June 15, 2022, this site no longer supports Internet Explorer. Please use another browser for the best experience on our site.

Product support

Security Advisories

SUMMARY

ioLogik 2542-HSPA Series Controllers and I/Os, and IOxpress Configuration Utility Vulnerabilities

  • Security Advisory ID: MPSA-190902
  • Version: V1.0
  • Release Date: Sep 25, 2019
  • Reference:
    • CVE-2019-18238, CVE-2020-7003, CVE-2019-18242

Multiple product vulnerabilities were identified in Moxa’s ioLogik 2542-HSPA Series Controllers and I/Os, and IOxpress Configuration Utility. In response to this, Moxa has developed related solutions to address these vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Use Weak Cryptographic Algorithms (CWE-310), CVE-2018-18238 The configuration file was not encrypted. If an attacker got hold of the file, sensitive information in the device could be disclosed.
2 Cleartext Storage and Transmission of Sensitive Information (CWE-312 and CWE-319), CVE-2020-7003 The configuration file was not encrypted. If an attacker got hold of the file, sensitive information in the device could be disclosed.
3 Denial-of-service attack (CWE-400, CWE-941), CVE-2019-18242 Frequent and multiple requests for short-term use may cause the web server to fail.
AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
ioLogik 2500 Series Firmware Version 3.0 or lower
IOxpress Configuration Utility Version 2.3.0 or lower

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
ioLogik 2500 Series Please contact Moxa Technical Support to get the security patch.
IOxpress Configuration Utility Please contact Moxa Technical Support to get the security patch.

Acknowledgment:

We would like to express our appreciation to Ilya Karpov and Evgeniy Druzhinin of Rostelecom-Solar for reporting the vulnerability, working with us to help enhance the security of our products, and helping us provide a better service to our customers.

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Sep 25, 2019

Relevant Products

ioLogik 2500 Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag
You have some items waiting in your bag; click here to finish your quote!
Feedback