Vulnerability in IP Forwarding Capabilities Could Allow Attacker to Bypass Access Controls or Hide Source of Malicious Requests

CVE-2024-0387
6.5MEDIUM

Key Information

Vendor
Moxa
Status
Eds-4008 Series
Eds-4009 Series
Eds-4012 Series
Eds-4014 Series
Vendor
CVE Published:
26 February 2024

Summary

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

Affected Version(s)

EDS-4008 Series <= 3.2

EDS-4009 Series <= 3.2

EDS-4012 Series <= 3.2

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.