VORANT. Threat Intelligence Sign in Get the full feed

Moxa switches vulnerable to TLS DoS flaw

routine vulnerability manufacturinginfrastructureenergy

An old TLS client-initiated renegotiation DoS vulnerability affects several Moxa industrial switch product lines with fixes available.

The French cybersecurity agency ANSSI issued an advisory covering multiple Moxa industrial networking products, including EDS-510A, ICS-G7826A, and several SDS-3000/G3000 series switches. The vulnerability, tracked as CVE-2011-1473, relates to TLS client-initiated renegotiation and can be exploited remotely to cause a denial-of-service condition on affected devices.

This is a long-known TLS protocol weakness (originally disclosed in 2011) that Moxa has now addressed in updated firmware versions for its industrial switch product lines, as detailed in Moxa security bulletin mpsa-262810 published August 19, 2026. Organizations using these Moxa devices in operational technology or industrial control environments should apply the vendor-supplied patches to remediate the risk. No evidence of active exploitation is noted in the advisory.

Mentioned in this report

Vulnerabilities CVE-2011-1473

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1055

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free