CVE-2023-28697 CRITICAL

CVE-2023-28697: Moxa MiiNePort E1 - Broken Access Control

Vendor Moxa
Product MiiNePort E1
Weakness CWE-306 · Missing auth
Published April 27, 2023
Last update January 31, 2025

CVSS base score

9.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Moxa MiiNePort E1 has a vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to perform arbitrary system operation or disrupt service.

Key dates

02Disclosure timeline

April 27, 2023 CVE published
January 31, 2025 Record updated