CVE-2023-5962

A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*

History

28 Oct 2024, 07:15

Type Values Removed Values Added
CWE CWE-328
Summary (en) A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization. (en) A weak cryptographic algorithm vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. This vulnerability can help an attacker compromise the confidentiality of sensitive data. This vulnerability may lead an attacker to get unexpected authorization.

03 Jan 2024, 20:04

Type Values Removed Values Added
CPE cpe:2.3:o:moxa:iologik_e1211_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1210:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1213_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1240:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1212:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1212_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1211:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1260:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1214_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1262:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1241:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1213:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1242_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1242:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:iologik_e1214:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:iologik_e1241_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-327
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-235250-iologik-e1200-series-web-server-vulnerability - Vendor Advisory

23 Dec 2023, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-23 09:15

Updated : 2024-10-28 07:15


NVD link : CVE-2023-5962

Mitre link : CVE-2023-5962

CVE.ORG link : CVE-2023-5962


JSON object : View

Products Affected

moxa

  • iologik_e1212_firmware
  • iologik_e1210_firmware
  • iologik_e1211
  • iologik_e1213
  • iologik_e1262
  • iologik_e1240
  • iologik_e1241_firmware
  • iologik_e1241
  • iologik_e1240_firmware
  • iologik_e1242_firmware
  • iologik_e1214_firmware
  • iologik_e1210
  • iologik_e1212
  • iologik_e1260
  • iologik_e1262_firmware
  • iologik_e1260_firmware
  • iologik_e1214
  • iologik_e1242
  • iologik_e1211_firmware
  • iologik_e1213_firmware
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-328

Reversible One-Way Hash