Moxa Security Enhancement: TLS Client Initiated Renegotiation

Act NowMPSA-262810Aug 19, 2026
Mitsubishi ElectricMoxa
Summary

TLS client-initiated renegotiation (CVE-2011-1473) is a design characteristic of the TLS protocol that could be abused to launch denial-of-service attacks under certain conditions. The vulnerability does not affect confidentiality or integrity of data. Moxa has disabled support for client-initiated TLS renegotiation in updated releases to align with current security best practices. Practical exploitability is considered low when products are deployed within recommended network-segmented architecture.

What this means
What could happen
An attacker with network access to the TLS connection could potentially cause a denial-of-service condition by forcing repetitive TLS renegotiations, disrupting communication with the affected device. Data confidentiality and integrity are not compromised by this issue.
Who's at risk
Moxa and Mitsubishi Electric industrial devices that use TLS for secure communication. This affects any ICS/OT environment where these devices are exposed to untrusted networks or lack proper network segmentation, including water treatment plants, power distribution systems, and manufacturing facilities with remote management or monitoring capabilities.
How it could be exploited
An attacker positioned on the network path to the device (man-in-the-middle) could send specially crafted TLS renegotiation requests to force the device to repeatedly renegotiate the TLS session, consuming resources and potentially disrupting normal operations or device responsiveness.
Prerequisites
  • Network access to the TLS connection on the affected device
  • Device must be accessible from an untrusted network or have no network segmentation
remotely exploitablehigh EPSS score (67.2%)no authentication requiredaffects network availability
Exploitability
Likely to be exploited — EPSS score 67.2%
Public Proof-of-Concept (PoC) on GitHub (3 repositories)
Affected products (1)
ProductAffected VersionsFix Status
Security Enhancement: TLS Client Initiated RenegotiationAll versionsNo fix yet
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXIf the device manufacturer has released a security update that disables client-initiated TLS renegotiation, apply it during a planned maintenance window
Long-term hardening
0/2
HARDENINGDeploy network segmentation to isolate the affected device from untrusted networks, ensuring only authorized systems can initiate connections
HARDENINGConfigure firewall rules or access control lists to restrict connections to the device to only necessary source IP addresses and systems
API: /api/v1/advisories/64a97652-0a4e-4627-afc1-7310a8ac9882

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Moxa Security Enhancement: TLS Client Initiated Renegotiation - OTPulse