Moxa ioLogik 2542-HSPA Series Controllers and IOs, and IOxpress Configuration Utility
Multiple vulnerabilities exist in Moxa ioLogik 2500 series controllers (firmware version 3.0 and earlier) and IOxpress configuration utility (version 2.3.0 and earlier). The vulnerabilities include sensitive data transmitted in cleartext (CWE-319), insufficient data protection (CWE-312), and a generic flaw in handling data (CWE-941). Successful exploitation could crash the device or allow unauthorized access to sensitive configuration information without authentication. The vulnerabilities are remotely exploitable over the network.
- Network access to ioLogik 2500 series controller or IOxpress configuration utility on the same network segment
- No valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/25cfc82e-b13f-431c-a021-cc7a9aceb493Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.