CVE-2020-28144

Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
moxaedr-g903_firmware
𝑥
≤ 5.5
moxaedr-g903-t_firmware
𝑥
≤ 5.5
moxaedr-g902_firmware
𝑥
≤ 5.5
moxaedr-g902-t_firmware
𝑥
≤ 5.5
moxaedr-810-2gsfp_firmware
𝑥
≤ 5.6
moxaedr-810-2gsfp-t_firmware
𝑥
≤ 5.6
moxaedr-810-vpn-2gsfp_firmware
𝑥
≤ 5.6
moxaedr-810-vpn-2gsfp-t_firmware
𝑥
≤ 5.6
𝑥
= Vulnerable software versions