An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-04 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-03-07T16:54:21.053Z

Updated: 2023-03-07T16:54:21.053Z

Reserved: 2023-03-07T16:16:20.728Z


Link: CVE-2023-1257

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-03-07T17:15:12.527

Modified: 2023-11-07T04:02:56.573


Link: CVE-2023-1257

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.