CVE-2020-28144

EUVD-2020-20630
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
moxaedr-g903_firmware
𝑥
≤ 5.5
moxaedr-g903-t_firmware
𝑥
≤ 5.5
moxaedr-g902_firmware
𝑥
≤ 5.5
moxaedr-g902-t_firmware
𝑥
≤ 5.5
moxaedr-810-2gsfp_firmware
𝑥
≤ 5.6
moxaedr-810-2gsfp-t_firmware
𝑥
≤ 5.6
moxaedr-810-vpn-2gsfp_firmware
𝑥
≤ 5.6
moxaedr-810-vpn-2gsfp-t_firmware
𝑥
≤ 5.6
𝑥
= Vulnerable software versions