Vulnerability in IP Forwarding Capabilities Could Allow Attacker to Bypass Access Controls or Hide Source of Malicious Requests
CVE-2024-0387
6.5MEDIUM
Key Information:
- Vendor
Moxa
- Vendor
- CVE Published:
- 26 February 2024
What is CVE-2024-0387?
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
Affected Version(s)
EDS-4008 Series 1.0 <= 3.2
EDS-4009 Series 1.0 <= 3.2
EDS-4012 Series 1.0 <= 3.2