Vulnerability Description
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Eds-4008 Firmware | <= 3.2 |
| Moxa | Eds-4008 | - |
| Moxa | Eds-4009 Firmware | <= 3.2 |
| Moxa | Eds-4009 | - |
| Moxa | Eds-4012 Firmware | <= 3.2 |
| Moxa | Eds-4012 | - |
| Moxa | Eds-4014 Firmware | <= 3.2 |
| Moxa | Eds-4014 | - |
| Moxa | Eds-G4008 Firmware | <= 3.2 |
| Moxa | Eds-G4008 | - |
| Moxa | Eds-G4012 Firmware | <= 3.2 |
| Moxa | Eds-G4012 | - |
| Moxa | Eds-G4014 Firmware | <= 3.2 |
| Moxa | Eds-G4014 | - |
Related Weaknesses (CWE)
References
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-237129-edVendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-237129-edVendor Advisory
FAQ
What is CVE-2024-0387?
CVE-2024-0387 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the ta...
How severe is CVE-2024-0387?
CVE-2024-0387 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0387?
Check the references section above for vendor advisories and patch information. Affected products include: Moxa Eds-4008 Firmware, Moxa Eds-4008, Moxa Eds-4009 Firmware, Moxa Eds-4009, Moxa Eds-4012 Firmware.