Description
A vulnerability has been identified in NPort 6000 Series, making the authentication mechanism vulnerable. This vulnerability arises from the incorrect implementation of sensitive information protection, potentially allowing malicious users to gain unauthorized access to the web service.
Problem types
CWE-303: Incorrect Implementation of Authentication Algorithm
CWE-257: Storing Passwords in a Recoverable Format
CWE-327: Use of a Broken or Risky Cryptographic Algorithm
Product status
1.0 (custom)
Credits
Pasha Kravtsov and Nathan Nye from True Anomaly (trueanomaly.space)
References
www.moxa.com/...on-of-authentication-algorithm-vulnerability
www.moxa.com/...on-of-authentication-algorithm-vulnerability