All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.

Project Subscriptions

Vendors Products
Nport 5100 Subscribe
Nport 5100a Subscribe
Nport 5100ai M12 Subscribe
Nport 5110 Subscribe
Nport 5110-t Subscribe
Nport 5110-t Firmware Subscribe
Nport 5110 Firmware Subscribe
Nport 5110a Subscribe
Nport 5110a-t Subscribe
Nport 5110a-t Firmware Subscribe
Nport 5110a Firmware Subscribe
Nport 5130 Subscribe
Nport 5130 Firmware Subscribe
Nport 5130a Subscribe
Nport 5130a-t Subscribe
Nport 5130a-t Firmware Subscribe
Nport 5130a Firmware Subscribe
Nport 5150 Subscribe
Nport 5150 Firmware Subscribe
Nport 5150a Subscribe
Nport 5150a-t Subscribe
Nport 5150a-t Firmware Subscribe
Nport 5150a Firmware Subscribe
Nport 5150ai-m12 Subscribe
Nport 5150ai-m12-ct Subscribe
Nport 5150ai-m12-ct-t Subscribe
Nport 5150ai-m12-ct-t Firmware Subscribe
Nport 5150ai-m12-ct Firmware Subscribe
Nport 5150ai-m12-t Subscribe
Nport 5150ai-m12-t Firmware Subscribe
Nport 5150ai-m12 Firmware Subscribe
Nport 5200 Series Firmware Subscribe
Nport 5200a Series Firmware Subscribe
Nport 5210 Subscribe
Nport 5210-t Subscribe
Nport 5210-t Firmware Subscribe
Nport 5210 Firmware Subscribe
Nport 5210a Subscribe
Nport 5210a-t Subscribe
Nport 5210a-t Firmware Subscribe
Nport 5210a Firmware Subscribe
Nport 5230 Subscribe
Nport 5230-t Subscribe
Nport 5230-t Firmware Subscribe
Nport 5230 Firmware Subscribe
Nport 5230a Subscribe
Nport 5230a-t Subscribe
Nport 5230a-t Firmware Subscribe
Nport 5230a Firmware Subscribe
Nport 5232 Subscribe
Nport 5232-t Subscribe
Nport 5232-t Firmware Subscribe
Nport 5232 Firmware Subscribe
Nport 5232i Subscribe
Nport 5232i-t Subscribe
Nport 5232i-t Firmware Subscribe
Nport 5232i Firmware Subscribe
Nport 5250a Subscribe
Nport 5250a-t Subscribe
Nport 5250a-t Firmware Subscribe
Nport 5250a Firmware Subscribe
Nport 5250ai-m12 Subscribe
Nport 5250ai-m12-ct Subscribe
Nport 5250ai-m12-ct-t Subscribe
Nport 5250ai-m12-ct-t Firmware Subscribe
Nport 5250ai-m12-ct Firmware Subscribe
Nport 5250ai-m12-t Subscribe
Nport 5250ai-m12-t Firmware Subscribe
Nport 5250ai-m12 Firmware Subscribe
Nport 5410 Subscribe
Nport 5410 Firmware Subscribe
Nport 5430 Subscribe
Nport 5430 Firmware Subscribe
Nport 5450 Subscribe
Nport 5450-t Subscribe
Nport 5450-t Firmware Subscribe
Nport 5450 Firmware Subscribe
Nport 5450ai-m12 Subscribe
Nport 5450ai-m12-ct Subscribe
Nport 5450ai-m12-ct-t Subscribe
Nport 5450ai-m12-ct-t Firmware Subscribe
Nport 5450ai-m12-ct Firmware Subscribe
Nport 5450ai-m12-t Subscribe
Nport 5450ai-m12-t Firmware Subscribe
Nport 5450ai-m12 Firmware Subscribe
Nport 5450i Subscribe
Nport 5450i-t Subscribe
Nport 5450i-t Firmware Subscribe
Nport 5450i Firmware Subscribe
Nport 5600 Dt Subscribe
Nport 5600 Series Firmware Subscribe
Nport 5610-16 Subscribe
Nport 5610-16-48v Subscribe
Nport 5610-16-48v Firmware Subscribe
Nport 5610-16 Firmware Subscribe
Nport 5610-8 Subscribe
Nport 5610-8-48v Subscribe
Nport 5610-8-48v Firmware Subscribe
Nport 5610-8-dt Subscribe
Nport 5610-8-dt-j Subscribe
Nport 5610-8-dt-j Firmware Subscribe
Nport 5610-8-dt-t Subscribe
Nport 5610-8-dt-t Firmware Subscribe
Nport 5610-8-dt Firmware Subscribe
Nport 5610-8 Firmware Subscribe
Nport 5630-16 Subscribe
Nport 5630-16 Firmware Subscribe
Nport 5630-8 Subscribe
Nport 5630-8 Firmware Subscribe
Nport 5650-16 Subscribe
Nport 5650-16-hv-t Subscribe
Nport 5650-16-hv-t Firmware Subscribe
Nport 5650-16-m-sc Subscribe
Nport 5650-16-m-sc Firmware Subscribe
Nport 5650-16-s-sc Subscribe
Nport 5650-16-s-sc Firmware Subscribe
Nport 5650-16-t Subscribe
Nport 5650-16-t Firmware Subscribe
Nport 5650-16 Firmware Subscribe
Nport 5650-8 Subscribe
Nport 5650-8-dt Subscribe
Nport 5650-8-dt-j Subscribe
Nport 5650-8-dt-j Firmware Subscribe
Nport 5650-8-dt-t Subscribe
Nport 5650-8-dt-t Firmware Subscribe
Nport 5650-8-dt Firmware Subscribe
Nport 5650-8-hv-t Subscribe
Nport 5650-8-hv-t Firmware Subscribe
Nport 5650-8-m-sc Subscribe
Nport 5650-8-m-sc Firmware Subscribe
Nport 5650-8-s-sc Subscribe
Nport 5650-8-s-sc Firmware Subscribe
Nport 5650-8-t Subscribe
Nport 5650-8-t Firmware Subscribe
Nport 5650-8 Firmware Subscribe
Nport 5650i-8-dt Subscribe
Nport 5650i-8-dt-t Subscribe
Nport 5650i-8-dt-t Firmware Subscribe
Nport 5650i-8-dt Firmware Subscribe
Nport Ia-5150 Subscribe
Nport Ia-5150-m-sc Subscribe
Nport Ia-5150-m-sc-t Subscribe
Nport Ia-5150-m-sc-t Firmware Subscribe
Nport Ia-5150-m-sc Firmware Subscribe
Nport Ia-5150-m-st Subscribe
Nport Ia-5150-m-st-t Subscribe
Nport Ia-5150-m-st-t Firmware Subscribe
Nport Ia-5150-m-st Firmware Subscribe
Nport Ia-5150-s-sc Subscribe
Nport Ia-5150-s-sc-t Subscribe
Nport Ia-5150-s-sc-t Firmware Subscribe
Nport Ia-5150-s-sc Firmware Subscribe
Nport Ia-5150-t Subscribe
Nport Ia-5150-t Firmware Subscribe
Nport Ia-5150 Firmware Subscribe
Nport Ia-5150i Subscribe
Nport Ia-5150i-m-sc Subscribe
Nport Ia-5150i-m-sc-t Subscribe
Nport Ia-5150i-m-sc-t Firmware Subscribe
Nport Ia-5150i-m-sc Firmware Subscribe
Nport Ia-5150i-s-sc Subscribe
Nport Ia-5150i-s-sc-t Subscribe
Nport Ia-5150i-s-sc-t Firmware Subscribe
Nport Ia-5150i-s-sc Firmware Subscribe
Nport Ia-5150i-t Subscribe
Nport Ia-5150i-t Firmware Subscribe
Nport Ia-5150i Firmware Subscribe
Nport Ia-5250 Subscribe
Nport Ia-5250-t Subscribe
Nport Ia-5250-t Firmware Subscribe
Nport Ia-5250 Firmware Subscribe
Nport Ia-5250i Subscribe
Nport Ia-5250i-t Subscribe
Nport Ia-5250i-t Firmware Subscribe
Nport Ia-5250i Firmware Subscribe
Nport Ia5000a-i\/o Subscribe
Nport Ia5000a-i\/o Firmware Subscribe
Nport Ia5150a Subscribe
Nport Ia5150a-iex Subscribe
Nport Ia5150a-iex Firmware Subscribe
Nport Ia5150a-t Subscribe
Nport Ia5150a-t-iex Subscribe
Nport Ia5150a-t-iex Firmware Subscribe
Nport Ia5150a-t Firmware Subscribe
Nport Ia5150a Firmware Subscribe
Nport Ia5150ai Subscribe
Nport Ia5150ai-iex Subscribe
Nport Ia5150ai-iex Firmware Subscribe
Nport Ia5150ai-t Subscribe
Nport Ia5150ai-t-iex Subscribe
Nport Ia5150ai-t-iex Firmware Subscribe
Nport Ia5150ai-t Firmware Subscribe
Nport Ia5150ai Firmware Subscribe
Nport Ia5250a Subscribe
Nport Ia5250a-iex Subscribe
Nport Ia5250a-iex Firmware Subscribe
Nport Ia5250a-t Subscribe
Nport Ia5250a-t-iex Subscribe
Nport Ia5250a-t-iex Firmware Subscribe
Nport Ia5250a-t Firmware Subscribe
Nport Ia5250a Firmware Subscribe
Nport Ia5250ai Subscribe
Nport Ia5250ai-iex Subscribe
Nport Ia5250ai-iex Firmware Subscribe
Nport Ia5250ai-t Subscribe
Nport Ia5250ai-t-iex Subscribe
Nport Ia5250ai-t-iex Firmware Subscribe
Nport Ia5250ai-t Firmware Subscribe
Nport Ia5250ai Firmware Subscribe
Nport Ia5450a Subscribe
Nport Ia5450a-t Subscribe
Nport Ia5450a-t Firmware Subscribe
Nport Ia5450a Firmware Subscribe
Nport Ia5450ai Subscribe
Nport Ia5450ai-t Subscribe
Nport Ia5450ai-t Firmware Subscribe
Nport Ia5450ai Firmware Subscribe
Nport Ia 5000 Subscribe
Nport Ia 5000a Subscribe
Nport Ia 5000a Io Subscribe
Nport Iaw5000a-i\/o Subscribe
Nport Iaw5000a-i\/o Firmware Subscribe
Nport Iaw 5000a Io Subscribe
Nport P5150a Subscribe
Nport P5150a-t Subscribe
Nport P5150a-t Firmware Subscribe
Nport P5150a Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-54765 All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.
Fixes

Solution

Due to design restrictions, we could not fix this vulnerability in NPort 5000 Series. We suggest users follow the instructions in the hardening guide https://www.moxa.com/getmedia/67b5e549-a125-4a6a-b99b-23017c75cfc1/moxa-the-security-hardening-guide-for-the-nport-5000-series-tech-note-v1.1.pdf in order to mitigate this vulnerability. Additionally, refer to the following mitigation measures to deploy the product in an appropriate product security context. Moxa recommends users follow these CISA recommendations. Users should * Reduce network exposure by ensuring that all control system devices and systems are not accessible from the Internet. * Place control system networks and remote devices behind firewalls, isolating them from business networks. * When remote access is necessary, employ secure methods such as Virtual Private Networks (VPNs). It is important to note that VPNs may have vulnerabilities and should be kept up to date with the latest available version. Remember that the security of a VPN depends on the security of its connected devices.


Workaround

No workaround given by the vendor.

History

Mon, 23 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Moxa nport 5100
Moxa nport 5100a
Moxa nport 5100ai M12
Moxa nport 5200 Series Firmware
Moxa nport 5200a Series Firmware
Moxa nport 5600 Dt
Moxa nport 5600 Series Firmware
Moxa nport Ia 5000
Moxa nport Ia 5000a
Moxa nport Ia 5000a Io
Moxa nport Iaw 5000a Io
CPEs cpe:2.3:a:moxa:nport_5100:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_5100ai_m12:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_5600_dt:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_5600_series_firmware:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_ia_5000:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_ia_5000a:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_ia_5000a_io:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_iaw_5000a_io:*:*:*:*:*:*:*:*
cpe:2.3:a:moxa:nport_p5150a:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_5100a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_5200_series_firmware:2.7:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_5200a_series_firmware:1.2:*:*:*:*:*:*:*
Vendors & Products Moxa nport 5100
Moxa nport 5100a
Moxa nport 5100ai M12
Moxa nport 5200 Series Firmware
Moxa nport 5200a Series Firmware
Moxa nport 5600 Dt
Moxa nport 5600 Series Firmware
Moxa nport Ia 5000
Moxa nport Ia 5000a
Moxa nport Ia 5000a Io
Moxa nport Iaw 5000a Io
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Moxa

Published:

Updated: 2024-09-23T13:29:04.471Z

Reserved: 2023-09-13T01:12:13.466Z

Link: CVE-2023-4929

cve-icon Vulnrichment

Updated: 2024-08-02T07:44:52.628Z

cve-icon NVD

Status : Modified

Published: 2023-10-03T14:15:11.307

Modified: 2024-11-21T08:36:17.250

Link: CVE-2023-4929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses