Impact
An improper validation of the username field in the web login processing of Moxa TN‑4500B Ethernet switches allows an attacker to supply an overly long input. The resulting out‑of‑bounds write causes a buffer overflow that can crash the authentication process, which in turn results in a denial of service. This flaw is classified as a CWE‑787 out‑of‑bounds write and presents a medium to high severity risk. The impact is limited to service disruption; there is no known path for privilege escalation or data compromise.
Affected Systems
Moxa TN‑4500B Series Ethernet switches, including firmware 2.1 and other unspecified revisions, are affected. The vulnerability is present in the web interface used for device configuration. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a very low current exploit probability. The flaw is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is a remote attacker accessing the device’s web management interface over a network to submit a crafted username input. Successful exploitation would result in the device’s authentication service crashing, causing a temporary denial of service until the device is rebooted or the service is restarted.
OpenCVE Enrichment