Moxa disclosed and patched CVE-2024-12297, a critical authorization flaw in multiple industrial Ethernet switch lines that can let a remote, unauthenticated attacker bypass authentication and access device functions. The vulnerability stems from weaknesses in frontend authorization logic and client-side versus back-end verification, allowing brute-force credential guessing and potential MD5 collision attacks to forge authentication hashes. Moxa rated the issue CVSS 9.2 and said exploitation could expose sensitive configurations or disrupt services on affected switches.
The flaw initially affected the EDS-508A Series on firmware 3.11 and earlier, and advisories later expanded coverage to additional EDS, SDS, and PT series models, including PT-508, PT-510, PT-7528, PT-7728, PT-7828, PT-G503, PT-G510, PT-G7728, and PT-G7828 below specified fixed versions. Moxa issued firmware updates for most impacted products and told some EDS-508A customers to obtain patches through technical support. The company also urged operators to minimize Internet exposure, restrict SSH and management access to trusted networks, apply least privilege and MFA where possible, and strengthen logging, IDS/IPS, and network monitoring around affected operational technology environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Moxa released fixes for CVE-2024-12297 affecting PT series industrial switches and EDS-508A series switches, and advised customers to install patches through its technical support channel. The updates addressed a critical remotely exploitable authorization flaw with a CVSS 9.2 score.
Moxa updated advisory MPSA-241407 to add multiple additional EDS and SDS series products and corresponding remediation guidance beyond the originally listed EDS-508A Series. The revision history states the update expanded affected products and solutions.
Moxa initially released security advisory MPSA-241407 for CVE-2024-12297, describing an authentication bypass vulnerability in EDS-508A Series switches that could enable brute-force credential guessing or MD5 collision attacks leading to unauthorized access or service disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.