CVE-2023-4452

EUVD-2023-54311
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them  vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot. 
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
MoxaCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
moxaedr-g903_firmware
𝑥
< 5.7.21
moxaedr-g903-t_firmware
𝑥
< 5.7.21
moxaedr-g902_firmware
𝑥
< 5.7.21
moxaedr-g902-t_firmware
𝑥
< 5.7.21
moxaedr-810-vpn-2gsfp_firmware
𝑥
< 5.12.29
moxaedr-810-vpn-2gsfp-t_firmware
𝑥
< 5.12.29
moxaedr-810-2gsfp_firmware
𝑥
< 5.12.29
moxaedr-810-2gsfp-t_firmware
𝑥
< 5.12.29
𝑥
= Vulnerable software versions