CVE-2024-0387
EDS-4000/G4000 Series IP Forwarding Vulnerability
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests.
Las series EDS-4000/G4000 anteriores a la versión 3.2 incluyen capacidades de reenvío de IP que los usuarios no pueden desactivar. Un atacante puede enviar solicitudes al producto y reenviarlas al objetivo. Un atacante puede eludir los controles de acceso u ocultar el origen de solicitudes maliciosas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-01-10 CVE Reserved
- 2024-02-26 CVE Published
- 2024-02-27 EPSS Updated
- 2024-10-28 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')
- CWE-1188: Initialization of a Resource with an Insecure Default
CAPEC
- CAPEC-465: Transparent Proxy Abuse
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | EDS-4008 Series Search vendor "Moxa" for product "EDS-4008 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-4008 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-4009 Series Search vendor "Moxa" for product "EDS-4009 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-4009 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-4012 Series Search vendor "Moxa" for product "EDS-4012 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-4012 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-4014 Series Search vendor "Moxa" for product "EDS-4014 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-4014 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-G4008 Series Search vendor "Moxa" for product "EDS-G4008 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-G4008 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-G4012 Series Search vendor "Moxa" for product "EDS-G4012 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-G4012 Series" and version " >= 1.0 <= 3.2" | en |
Affected
| ||||||
Moxa Search vendor "Moxa" | EDS-G4014 Series Search vendor "Moxa" for product "EDS-G4014 Series" | >= 1.0 <= 3.2 Search vendor "Moxa" for product "EDS-G4014 Series" and version " >= 1.0 <= 3.2" | en |
Affected
|