Vulnerability in IP Forwarding Capabilities Could Allow Attacker to Bypass Access Controls or Hide Source of Malicious Requests
CVE-2024-0387
6.5MEDIUM
Key Information
- Vendor
- Moxa
- Status
- Eds-4008 Series
- Eds-4009 Series
- Eds-4012 Series
- Eds-4014 Series
- Vendor
- CVE Published:
- 26 February 2024
Summary
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
Affected Version(s)
EDS-4008 Series <= 3.2
EDS-4009 Series <= 3.2
EDS-4012 Series <= 3.2
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database