// For flags

CVE-2024-0387

EDS-4000/G4000 Series IP Forwarding Vulnerability

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.

Las series EDS-4000/G4000 anteriores a la versión 3.2 incluyen capacidades de reenvío de IP que los usuarios no pueden desactivar. Un atacante puede enviar solicitudes al producto y reenviarlas al objetivo. Un atacante puede eludir los controles de acceso u ocultar el origen de solicitudes maliciosas.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-01-10 CVE Reserved
  • 2024-02-26 CVE Published
  • 2024-02-27 EPSS Updated
  • 2024-10-28 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
  • CWE-1188: Initialization of a Resource with an Insecure Default
CAPEC
  • CAPEC-465: Transparent Proxy Abuse
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Moxa
Search vendor "Moxa"
EDS-4008 Series
Search vendor "Moxa" for product "EDS-4008 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-4008 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-4009 Series
Search vendor "Moxa" for product "EDS-4009 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-4009 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-4012 Series
Search vendor "Moxa" for product "EDS-4012 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-4012 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-4014 Series
Search vendor "Moxa" for product "EDS-4014 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-4014 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-G4008 Series
Search vendor "Moxa" for product "EDS-G4008 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-G4008 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-G4012 Series
Search vendor "Moxa" for product "EDS-G4012 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-G4012 Series" and version " >= 1.0 <= 3.2"
en
Affected
Moxa
Search vendor "Moxa"
EDS-G4014 Series
Search vendor "Moxa" for product "EDS-G4014 Series"
>= 1.0 <= 3.2
Search vendor "Moxa" for product "EDS-G4014 Series" and version " >= 1.0 <= 3.2"
en
Affected