CVE-2024-7695
Description
An out-of-bounds write vulnerability in multiple Moxa switches allows unauthenticated remote attackers to cause a denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds write vulnerability in multiple Moxa switches allows unauthenticated remote attackers to cause a denial-of-service condition.
Vulnerability
CVE-2024-7695 is an out-of-bounds write vulnerability (CWE-787) affecting multiple Moxa switch series, including EDS, ICS, IKS, SDS, PT, and EN 50155 models [1][2][3]. The root cause is insufficient input validation, which permits writing data beyond the allocated buffer boundaries [1].
Exploitation
The vulnerability can be exploited remotely without authentication over the network [1][2]. The CVSS vector indicates low attack complexity and no user interaction required (AV:N/AC:L/PR:N/UI:N) [2][3]. An attacker can send specially crafted network packets to trigger the out-of-bounds write, leading to memory corruption.
Impact
Successful exploitation results in a denial-of-service (DoS) condition, potentially causing the affected switch to crash or become unresponsive [1][2]. There is no impact on confidentiality or integrity, but availability is compromised, which could disrupt industrial network operations.
Mitigation
Moxa has released security advisories (MPSA-240162, MPSA-240163, MPSA-240164) and recommends updating the firmware to the latest versions [1][2][3]. As a temporary workaround, restrict network access to the affected devices and monitor for malicious traffic.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.moxa.com/en/support/product-support/security-advisory/mpsa-240162-cve-2024-7695-out-of-bounds-write-vulnerability-identified-in-multiple-pt-switchesnvd
- www.moxa.com/en/support/product-support/security-advisory/mpsa-240163-cve-2024-7695-out-of-bounds-write-vulnerability-in-multiple-eds,-ics,-iks,-and-sds-switchesnvd
- www.moxa.com/en/support/product-support/security-advisory/mpsa-240164-cve-2024-7695-out-of-bounds-write-vulnerability-identified-in-en-50155-switchesnvd
News mentions
0No linked articles in our index yet.