SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-0387

An attacker may be able to send requests to the product and have it forwarded to the target.

MEDIUM 6.5EPSS 0.54%

Does this matter?

Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.

Description

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.54% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-1188
Affected
moxa/eds-4008 firmware · moxa/eds-4009 firmware · moxa/eds-4012 firmware · moxa/eds-4014 firmware · moxa/eds-g4008 firmware · moxa/eds-g4012 firmware · moxa/eds-g4014 firmware
Source
psirt@moxa.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.