<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:moxa:tn-4500b_series_firmware:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3amoxatn-4500b_series_firmware/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 19:45:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3amoxatn-4500b_series_firmware/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Denial of Service Vulnerability in Moxa TN-4500B Series</title><link>https://feed.craftedsignal.io/briefs/2026-09-moxa-dos/</link><pubDate>Fri, 18 Sep 2026 19:45:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-moxa-dos/</guid><description>A critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.</description><content:encoded><![CDATA[<p>Moxa has released security advisory MPSA-252620 detailing an out-of-bounds write vulnerability, identified as CVE-2026-15579, affecting the TN-4500B Series of industrial Ethernet switches. The vulnerability exists due to improper handling of input within the device's management interface. A remote, unauthenticated attacker can exploit this flaw by sending specially crafted packets to the affected hardware. Successful exploitation results in an immediate denial-of-service (DoS) condition, rendering the network switch unavailable and potentially disrupting critical industrial communication flows. All versions of the TN-4500B series prior to version 2.1 are affected.</p>
<h2 id="impact">Impact</h2>
<p>The impact of this vulnerability is significant, as it permits the disruption of industrial network infrastructure from a remote, unauthenticated position. Organizations relying on the TN-4500B series for critical communications or SCADA operations face an increased risk of operational downtime and loss of visibility into the managed network segments if the device enters a crashed state.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate patching of all vulnerable Moxa TN-4500B series switches.</p>
<ul>
<li>Upgrade all affected units to firmware version 2.1 or later as specified in Moxa Security Advisory MPSA-252620.</li>
<li>Restrict network access to the switch management interfaces using firewalls or ACLs to prevent unauthenticated remote access to the vulnerable service until patching is complete.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>industrial-control-systems</category><category>denial-of-service</category><category>network-device</category></item></channel></rss>