CVE-2023-1257

HIGH

Moxa UC Series - Privilege Escalation

Title source: llm
STIX 2.1

Description

An attacker with physical access to the affected Moxa UC Series devices can initiate a restart of the device and gain access to its BIOS. Command line options can then be altered, allowing the attacker to access the terminal. From the terminal, the attacker can modify the device’s authentication files to create a new user and gain full access to the system.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-333-04

Scores

CVSS v3 7.6
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (50)
moxa/uc-2101-lx_firmware 1.3 - 1.5
moxa/uc-2102-lx_firmware 1.3 - 1.5
moxa/uc-2102-t-lx_firmware 1.3 - 1.5
moxa/uc-2104-lx_firmware 1.3 - 1.5
moxa/uc-2111-lx_firmware 1.3 - 1.5
moxa/uc-2112-lx_firmware 1.3 - 1.5
moxa/uc-2114-t-lx_firmware
moxa/uc-2114-t-lx_firmware 1.3 - 1.5
moxa/uc-2116-t-lx_firmware 1.3 - 1.5
moxa/uc-3101-t-ap-lx_firmware 1.2 - 2.0
... and 40 more
Published Mar 07, 2023
Tracked Since Feb 18, 2026