CVE-2020-28144
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Determinados productos de Moxa Inc están afectados por una restricción inapropiada de operaciones en EDR-G903 Series Versión de Firmware 5.5 o inferiores, EDR-G902 Series Versión de Firmware 5.5 o inferiores, y EDR-810 Series Versión de Firmware 5.6 o inferiores. Unas peticiones diseñadas enviadas al dispositivo pueden permitir una ejecución de código arbitraria remota
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-11-02 CVE Reserved
- 2021-02-03 CVE Published
- 2024-08-04 CVE Updated
- 2024-11-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Edr-g903 Firmware Search vendor "Moxa" for product "Edr-g903 Firmware" | <= 5.5 Search vendor "Moxa" for product "Edr-g903 Firmware" and version " <= 5.5" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-g903 Search vendor "Moxa" for product "Edr-g903" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-g903-t Firmware Search vendor "Moxa" for product "Edr-g903-t Firmware" | <= 5.5 Search vendor "Moxa" for product "Edr-g903-t Firmware" and version " <= 5.5" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-g903-t Search vendor "Moxa" for product "Edr-g903-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-g902 Firmware Search vendor "Moxa" for product "Edr-g902 Firmware" | <= 5.5 Search vendor "Moxa" for product "Edr-g902 Firmware" and version " <= 5.5" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-g902 Search vendor "Moxa" for product "Edr-g902" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-g902-t Firmware Search vendor "Moxa" for product "Edr-g902-t Firmware" | <= 5.5 Search vendor "Moxa" for product "Edr-g902-t Firmware" and version " <= 5.5" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-g902-t Search vendor "Moxa" for product "Edr-g902-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-810-2gsfp Firmware Search vendor "Moxa" for product "Edr-810-2gsfp Firmware" | <= 5.6 Search vendor "Moxa" for product "Edr-810-2gsfp Firmware" and version " <= 5.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-810-2gsfp Search vendor "Moxa" for product "Edr-810-2gsfp" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-810-2gsfp-t Firmware Search vendor "Moxa" for product "Edr-810-2gsfp-t Firmware" | <= 5.6 Search vendor "Moxa" for product "Edr-810-2gsfp-t Firmware" and version " <= 5.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-810-2gsfp-t Search vendor "Moxa" for product "Edr-810-2gsfp-t" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-810-vpn-2gsfp Firmware Search vendor "Moxa" for product "Edr-810-vpn-2gsfp Firmware" | <= 5.6 Search vendor "Moxa" for product "Edr-810-vpn-2gsfp Firmware" and version " <= 5.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-810-vpn-2gsfp Search vendor "Moxa" for product "Edr-810-vpn-2gsfp" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Edr-810-vpn-2gsfp-t Firmware Search vendor "Moxa" for product "Edr-810-vpn-2gsfp-t Firmware" | <= 5.6 Search vendor "Moxa" for product "Edr-810-vpn-2gsfp-t Firmware" and version " <= 5.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Edr-810-vpn-2gsfp-t Search vendor "Moxa" for product "Edr-810-vpn-2gsfp-t" | - | - |
Safe
|