CERT-In Vulnerability Note
CIVN-2021-0387
Memory Leak Vulnerability in MOXA Devices
Original Issue Date:December 31, 2021
Severity Rating: HIGH
Software Affected
- MGate 5109 Series Protocol Gateway: Firmware Version 2.2 and prior
- MGate 5101-PBM-MN Series Protocol Gateway: Firmware Version 2.1 and prior
- TN-5900 Series: Firmware Version 3.1 and prior
Overview
A vulnerability has been reported in MOXA Devices which could allow a remote attacker to cause memory leak on the targeted system.
Description
A vulnerability exists in MOXA Devices due to vulnerable firmware. A remote attacker could exploit this vulnerability by continuously sending crafted packets to cause memory leak on the targeted systems.
Successful exploitation of this vulnerability could allow a remote attacker to cause memory leak on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://www.moxa.com/en/support/product-support/security-advisory/mgate-5109-5101-protocol-gateways-vulnerability
https://www.moxa.com/en/support/product-support/security-advisory/tn-5900-secure-routers-vulnerability
Vendor Information
MOXA
https://www.moxa.com/en/support/product-support/security-advisory/mgate-5109-5101-protocol-gateways-vulnerability
https://www.moxa.com/en/support/product-support/security-advisory/tn-5900-secure-routers-vulnerability
References
MOXA
https://www.moxa.com/en/support/product-support/security-advisory/mgate-5109-5101-protocol-gateways-vulnerability
https://www.moxa.com/en/support/product-support/security-advisory/tn-5900-secure-routers-vulnerability
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|