QID 590836

QID 590836: MOXA Device Manager Buffer Overflow (Update A) Vulnerability (ICSA-10-301-01A)

A

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

MOXAs embedded device products are implemented in a variety of industrial control solutions making it difficult to ascertain where and how the products are used. to individual organizations depends on many factors that are unique to each organization. ICS-CERT recommends that organizations evaluate the impact of this vulnerability based on their environment, architecture, and product implementation.BackgroundMDM 2.1 is a freeware software product developed by MOXA for users to manage MOXAs embedded computers. MOXA devices are used in a wide variety of applications across a wide range of industries including substation monitoring, manufacturing, telecommunications, medical, etc. MOXA has offices in Taiwan (HQ), China, Germany, and Brea, California while the heaviest concentration of Moxa distributors is in the United States.

  • CVSS V3 rated as Medium - 4 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-10-301-01A for affected packages and patching details.

    Vendor References

    CVEs related to QID 590836

    Software Advisories
    Advisory ID Software Component Link
    ICSA-10-301-01A URL Logo www.us-cert.gov/ics/advisories/ICSA-10-301-01A

    © CVE.report 2026

    Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

    CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

    Free CVE JSON API cve.report/api

    CVE.report and Source URL Uptime Status status.cve.report