CVE-2024-12297 is a critical authentication bypass vulnerability affecting multiple Moxa Ethernet switch product lines, including EDS-508A and additional EDS, SDS, PT, TN-A, and TN-G series firmware branches identified by the vendor. The flaw is described as a weakness in the device authorization mechanism, specifically in the implementation of frontend authorization logic involving both client-side and back-end server verification. Weaknesses in that design and implementation allow an unauthenticated remote attacker to undermine the intended authentication process. Reported exploitation paths include brute-force attacks to guess valid credentials and MD5 collision attacks to forge authentication hashes, enabling bypass of authorization controls and unauthorized access to the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass vulnerability affecting Moxa PT switches.
A critical authentication/authorization logic vulnerability in Moxa PT series and EDS-508A industrial switches that could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized access, including via brute-force and MD5-collision-based attacks to obtain valid credentials or authentication hashes.
A critical authentication bypass / authorization logic flaw in Moxa EDS-508A Series Ethernet switches (firmware 3.11 and earlier) that can allow unauthenticated remote attackers to bypass authentication and gain unauthorized access, impacting confidentiality, integrity, and availability.
A frontend authorization logic disclosure vulnerability affecting certain Moxa Ethernet switch product lines.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.