PT-2020-5381 · Moxa · Edr-G903 Series+2
Xinjie Ma
·
Published
2020-11-03
·
Updated
2021-02-05
·
CVE-2020-28144
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa Inc EDR-G903 Series versions 5.5 or lower
Moxa Inc EDR-G902 Series versions 5.5 or lower
Moxa Inc EDR-810 Series versions 5.6 or lower
Description
The issue is related to an improper restriction of operations, which may allow remote arbitrary code execution when crafted requests are sent to the device. This can be exploited by a remote attacker using specially formed requests, potentially leading to denial of service. The vulnerability is also described as a buffer overflow in memory, which can be triggered by a crafted request.
Recommendations
For EDR-G903 Series versions 5.5 or lower, update to a version higher than 5.5 to resolve the issue.
For EDR-G902 Series versions 5.5 or lower, update to a version higher than 5.5 to resolve the issue.
For EDR-810 Series versions 5.6 or lower, update to a version higher than 5.6 to resolve the issue.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edr-810 Series
Edr-G902 Series
Edr-G903 Series