« Volver al listado

CVE-2025-15017

Estado: AplazadaAlta (7)—

A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access to internal debug functionality. Exploitation is low complexity and allows an attacker to execute privileged operations and access sensitive system resources, resulting in a high impact to the confidentiality, integrity, and availability of the affected device. No security impact to external or dependent systems has been identified.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso físico (AV:P) a interfaz UART sin autenticación permite ejecución privilegiada de operaciones y acceso a recursos sensibles del sistema. Impactos: ejecución de código, lectura de datos e integridad del dispositivo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-15017",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-15017",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-31T16:06:25.868011Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "psirt@moxa.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "PHYSICAL",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@moxa.com",
      "affectedData": [
        {
          "vendor": "Moxa",
          "product": "NPort 5000AI-M12 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5100 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5100A Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5200 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5200A Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5400 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5600 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort 5600-DT Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort IA5000 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort IA5000A Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "Moxa",
          "product": "NPort IA5000-G2 Series",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-31T08:15:44.303",
  "references": [
    {
      "url": "https://www.moxa.com/en/support/product-support/security-advisory/mpsa-257331-cve-2025-15017-active-debug-code-vulnerability-in-serial-device-servers",
      "source": "psirt@moxa.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@moxa.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-489"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with physical access to the device can directly connect to the UART interface and, without authentication, user interaction, or execution conditions, gain unauthorized access to internal debug functionality. Exploitation is low complexity and allows an attacker to execute privileged operations and access sensitive system resources, resulting in a high impact to the confidentiality, integrity, and availability of the affected device. No security impact to external or dependent systems has been identified."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad existe en servidores de dispositivos serie donde el código de depuración activo permanece habilitado en la interfaz UART. Un atacante con acceso físico al dispositivo puede conectarse directamente a la interfaz UART y, sin autenticación, interacción del usuario o condiciones de ejecución, obtener acceso no autorizado a la funcionalidad de depuración interna. La explotación es de baja complejidad y permite a un atacante ejecutar operaciones privilegiadas y acceder a recursos sensibles del sistema, resultando en un alto impacto a la confidencialidad, integridad y disponibilidad del dispositivo afectado. No se ha identificado ningún impacto de seguridad en sistemas externos o dependientes."
    }
  ],
  "lastModified": "2026-06-17T08:36:57.367",
  "sourceIdentifier": "psirt@moxa.com"
}