CVE-2024-12297Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-656

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-05: 2Mentions · 2026-02-06: 1Patch / Workaround · 2026-02-05: 2Technical Details · 2026-02-05: 202-0502-06
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-052
Disclosure1Patch1
2026-02-061
General1
Full discourse3 posts
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about this CVE from https://vulntracker.io/cves/CVE-2024-12297 for FREE

    Post summary

    The post only directs readers to a vulnerability tracker page for CVE‑2024‑12297, offering no additional details on exploitation, patches, or technical specifics.

    0000049
    333 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical Moxa TN-A/TN-G Switch Flaw (CVE-2024-12297) Enables Remote Auth Bypass on Industrial Networks Moxa disclosed a critical authentication weakness in TN-A/TN-G Ethernet switches where frontend/back-end authorization gaps can be abused (e.g., brute-force and signature forgery via weak MD5-based logic) to gain unauthorized access to management interfaces, risking OT network tampering and lateral movement. Apply the vendor firmware updates and restrict management-plane access immediately. 🎯 Target: Global/OT & Industrial Networks #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/moxa-switches-vulnerability/

    Post summary

    Moxa disclosed a critical authentication flaw in its TN‑A/TN‑G switches that allows remote authentication bypass via brute‑force and MD5‑based forgery, and urges immediate firmware updates and network restrictions.

    0000079
    192 followersView on X
  • Sami Laiho@samilaiho
    Patch

    Frontend Authorization Logic Disclosure Vulnerability in Moxa Ethernet Switches URL: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241409-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-in-ethernet-switches Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.2

    Post summary

    Moxa issued a critical disclosure for CVE‑2024‑12297, providing a CVSS score of 9.2 and an official fix, but no exploitation or PoC information is available.

    00000465
    30.4K followersView on X

Explore more