Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-44336 | The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacker can pose as an authorized user and successfully access the resource. |
Solution
Moxa has developed an appropriate solution to address the vulnerability. The solution for the affected product is shown below. * MXsecurity: Please Upgrade to the firmware version 2.2.0 or higher via the Moxa Software Licensing Portal https://netsecuritylicense.moxa.com/Account/Login
Workaround
* Minimize network exposure to ensure the device is not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). * The starting point of all the above vulnerabilities is from the web service, so it is suggested to disable web service temporarily if you completed configuration to prevent further damages from these vulnerabilities until installed patch or updated firmware.
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 22 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-Other |
Fri, 18 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Moxa
Moxa mxsecurity |
|
CPEs | cpe:2.3:a:moxa:mxsecurity:*:*:*:*:*:*:*:* | |
Vendors & Products |
Moxa
Moxa mxsecurity |
|
Metrics |
ssvc
|
Fri, 18 Oct 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior vulnerable. By acquiring a valid authenticator, an attacker can pose as an authorized user and successfully access the resource. | |
Title | MXsecurity License Generation Function Disclosure | |
Weaknesses | CWE-749 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2024-10-18T14:40:34.104Z
Reserved: 2024-05-10T09:05:34.287Z
Link: CVE-2024-4739

Updated: 2024-10-18T14:40:27.471Z

Status : Analyzed
Published: 2024-10-18T09:15:03.710
Modified: 2024-10-22T14:07:02.023
Link: CVE-2024-4739

No data.

No data.