CVE-2024-0387
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
Published:Feb 26, 2024
Last Modified:Feb 25, 2025
EPS:Feb 26, 2024
EPSS Score:0.0027
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Moxa
Product
Eds-4008
Moxa
Eds-4008
Vendor
Moxa
Product
Eds-4008 Firmware
Moxa
Eds-4008 Firmware
Vendor
Moxa
Product
Eds-4009
Moxa
Eds-4009
Vendor
Moxa
Product
Eds-4009 Firmware
Moxa
Eds-4009 Firmware
Vendor
Moxa
Product
Eds-4012
Moxa
Eds-4012
Vendor
Moxa
Product
Eds-4012 Firmware
Moxa
Eds-4012 Firmware
Vendor
Moxa
Product
Eds-4014
Moxa
Eds-4014
Vendor
Moxa
Product
Eds-4014 Firmware
Moxa
Eds-4014 Firmware
Vendor
Moxa
Product
Eds-g4008
Moxa
Eds-g4008
Vendor
Moxa
Product
Eds-g4008 Firmware
Moxa
Eds-g4008 Firmware
Vendor
Moxa
Product
Eds-g4012
Moxa
Eds-g4012
Vendor
Moxa
Product
Eds-g4012 Firmware
Moxa
Eds-g4012 Firmware
Vendor
Moxa
Product
Eds-g4014
Moxa
Eds-g4014
Vendor
Moxa
Product
Eds-g4014 Firmware
Moxa
Eds-g4014 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
