A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Buffer Copy Without Checking Size of Input (CWE-120)
CVE-2023-4452
|
An attacker can trigger the device reboot. |
Vulnerability Scoring Details
| ID | CVSS V3.1 | VECTOR | REMOTE EXPLOIT WITHOUT AUTH? |
|---|---|---|---|
| CVE-2023-4452 | 6.5 | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-234880-edr-810-g902-g903-series-web-server-buffer-overflow-vulnerability