CVE-2024-12297 - CVE House
Back to Database
Status published Critical CVE-2024-12297

Frontend Authorization Logic Disclosure Vulnerability

Vulnerability Description

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12297

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Artem Turyshev from Rosatom Automated Control Systems Joint-Stock Company

Affected Vendor

Affected Software

EDS-508A Series, PT-508 Series, PT-510 Series, PT-7528 Series, PT-7728 Series, PT-7828 Series, PT-G503 Series, PT-G510 Series, PT-G7728 Series, PT-G7828 Series
Vulnerable Versions:
1.0

Timeline

Official Publish: January 15th, 2025
Last Modified: March 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.