CPATH-2026-0032 · General IoT

Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297)

Two or more co-dominant consequence paths connect the public security record to a provisional HIGH consequence band.

Candidate bandHIGH
Co-dominant pathsAccount authority + Device availability and recovery + Data privacy

These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Co-dominant path

Account authority

The bypass grants administration of forwarding and device settings, but not a Moxa signing key or firmware trust root.

HIGH
  1. accessSource-backed

    Network-reachable without prior access

    The authentication check sits on the switch management interface and is reachable wherever that OT management network is exposed.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    An administrative foothold on the switch can pivot across OT segments and change how control traffic is forwarded.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Administrative or command authority

    The bypass grants administration of forwarding and device settings, but not a Moxa signing key or firmware trust root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The bypass grants administration of forwarding and device settings, but not a Moxa signing key or firmware trust root.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Recovery is a firmware update and configuration verification, usually scheduled through constrained industrial maintenance windows.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The authentication check sits on the switch management interface and is reachable wherever that OT management network is exposed.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Forging the accepted hash requires brute force or an MD5-collision technique, making this a specialist but repeatable workflow.

Source-backedNVD
ExposureEX 2
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Switch administration can disrupt industrial communications, but it does not directly command a physical actuator.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Administrator access exposes switch configuration, firmware state, and sensitive operational details about the control network.

Model inference
AuthorityAT 3
Administrative or command authority

The bypass grants administration of forwarding and device settings, but not a Moxa signing key or firmware trust root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

An administrative foothold on the switch can pivot across OT segments and change how control traffic is forwarded.

Model inference
Reuse scaleSR 3
Portable product-class technique

The hash-forgery technique applies across the affected PT and EDS switch models without a universal secret.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

The technique can be repeated across reachable switches, but each site's management plane and hash work must be handled.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Recovery is a firmware update and configuration verification, usually scheduled through constrained industrial maintenance windows.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. The bypass grants administration of forwarding and device settings, but not a Moxa signing key or firmware trust root.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:2/EX:2/PH:2/DP:3/AT:3/CH:4/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Recovery · Co-dominant path

Device availability and recovery

Changing or disabling switch configuration can interrupt communications needed by industrial monitoring and control.

HIGH
  1. accessSource-backed

    Network-reachable without prior access

    The attacker must reach the industrial switch management interface on the control network.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    One compromised switch can propagate an outage into multiple connected OT devices and network segments.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Changing or disabling switch configuration can interrupt communications needed by industrial monitoring and control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Changing or disabling switch configuration can interrupt communications needed by industrial monitoring and control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Operators can restore configuration and apply fixed firmware during an approved OT maintenance window.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The attacker must reach the industrial switch management interface on the control network.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

The same brute-force or MD5-collision work is required before disruptive configuration changes can be made.

Source-backedNVD
ExposureEX 2
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Changing or disabling switch configuration can interrupt communications needed by industrial monitoring and control.

Model inference
Data / perceptionDP 1
Low-sensitivity state

This disruption-focused path does not depend on extracting sensitive process data.

Model inference
AuthorityAT 3
Administrative or command authority

Configuration authority is sufficient to change ports, forwarding, and availability of the switch.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

One compromised switch can propagate an outage into multiple connected OT devices and network segments.

Model inference
Reuse scaleSR 3
Portable product-class technique

The bypass method is reusable across affected Moxa models after site-specific setup.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

A deployment can contain many affected switches, but each reachable management plane must be targeted.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Operators can restore configuration and apply fixed firmware during an approved OT maintenance window.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Changing or disabling switch configuration can interrupt communications needed by industrial monitoring and control.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:2/EX:2/PH:2/DP:1/AT:3/CH:3/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Co-dominant path

Data privacy

Port mirroring can expose control-network traffic, device configuration, credentials, and proprietary process state.

HIGH
  1. accessSource-backed

    Network-reachable without prior access

    The switch management interface must be reachable from the attacker's network position.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Mirrored OT traffic can reveal credentials and protocols that support later movement into connected control systems.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Port mirroring can expose control-network traffic, device configuration, credentials, and proprietary process state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Port mirroring can expose control-network traffic, device configuration, credentials, and proprietary process state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Fixed firmware and verified switch configuration restore this path; captured credentials may need separate rotation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The switch management interface must be reachable from the attacker's network position.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Brute force or MD5-collision work is needed to bypass authentication before traffic mirroring can be configured.

Source-backedNVD
ExposureEX 2
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

Passive traffic collection does not directly change industrial actuation.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Port mirroring can expose control-network traffic, device configuration, credentials, and proprietary process state.

Model inference
AuthorityAT 3
Administrative or command authority

Switch configuration authority lets the attacker create mirror ports and redirect traffic for observation.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Mirrored OT traffic can reveal credentials and protocols that support later movement into connected control systems.

Model inference
Reuse scaleSR 3
Portable product-class technique

The same bypass and mirroring workflow can be reused across the affected switch models.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Collection can cover each reachable site after its management plane is accessed and configured.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Fixed firmware and verified switch configuration restore this path; captured credentials may need separate rotation.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Port mirroring can expose control-network traffic, device configuration, credentials, and proprietary process state.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:2/EX:2/PH:0/DP:3/AT:3/CH:3/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is lower
Baseline confidencehigh
Scored2026-06-03
v4.0 · 9.2 CRITICALMoxa PSIRT via NVD
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297) at HIGH — the worst of 3 risk paths (authority, safety, perception). The dominant consequence is privileged account or control authority.

Vulnerability

Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297). Reported attack vector: Network (remote, low attack complexity per CVSS v4 metrics; AV Network, AC Low).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

ACCOUNT_AUTHORITYHIGH

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:2/EX:2/PH:2/DP:3/AT:3/CH:4/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH → assessed HIGH.

Network-reachable management interface (RE:4 per AV:Network; though management-VLAN segmentation may reduce in practice, default exposure on flat OT nets drives 4). EC:2 because exploitation requires brute-force or MD5-collision hash forgery (advanced-but-reproducible, not a one-shot RCE). AT:3 admin/config authority over the switch (network forwarding/device settings) but not a signing-root/OTA root, so not 4. DP:3 config access exposes firmware/proprietary/sensitive-op-state. CH:4 admin foothold on OT infrastructure is a reusable cross-domain pivot (app/cloud/device/network boundary crossing). SR:3 reusable bypass technique across nine+ models but not a shared key/signing-root. SX:3 deployment-wide with setup since each device’s mgmt plane must be reached. PH:2 indirect availability/workflow disruption, no direct actuation. OR:2 recoverable via firmware patch though OT windows long. EV:2 report-backed (researcher-reported, advisory published, not publicly reproduced).

DEVICE_AVAILABILITYHIGH

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:2/EX:2/PH:2/DP:1/AT:3/CH:3/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=ELEVATED · DP=ELEVATED · AT=HIGH → base HIGH → assessed HIGH.

Post-bypass the attacker can disrupt service / alter switch forwarding behavior, breaking OT process communications. RE:4 same network-reachable mgmt surface. EC:2 same brute-force/collision effort. AT:3 config-level control of OT network device. PH:2 communications/availability disruption on the control network path; advisory notes no direct actuator control, so not 3/4 safety injury. DP:1 minimal data exposure on this disruption-focused path. CH:3 chains to broader OT outage. SR:3 reusable technique across models. SX:3 deployment-wide with per-site mgmt-plane reach. OR:2 patchable. EV:2 report-backed.

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:2/EX:2/PH:2/DP:3/AT:3/CH:3/SR:3/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (execution complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH · caps privacy-only cap → assessed HIGH.

  • Admin/config access enables port-mirroring and traffic manipulation to eavesdrop on OT/control-network traffic (confidentiality + integrity). RE:4 network mgmt surface. EC:2 brute-force/MD5-collision effort to reach config. AT:3 config authority enabling the mirroring. DP:3 sensitive operational/control-network traffic and config (firmware/proprietary state), not biometric/world-model so not 4.
  • perception_feeds_action — false: this is network/OT traffic data, not a sensor world-model that directly drives physical/navigation/therapy decisions. PH:0 no direct safety on the pure-eavesdrop path. CH:3 mirrored OT traffic/creds enable lateral movement. SR:3 reusable bypass across models. SX:3 deployment-wide with per-site reach. OR:2 patchable. EV:2 report-backed.

Published baseline

  • v4.0 9.2 CRITICAL — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — Moxa PSIRT via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path rather than treating the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0032 (“Moxa PT/EDS industrial Ethernet switch authentication bypass (CVE-2024-12297)”), paths.cfse.ai/CPATH-2026-0032 (published 2026-06-03).