CVE-2023-4452

A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them  vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot. 
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
MoxaCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
moxaedr-g903_firmware
𝑥
< 5.7.21
moxaedr-g903-t_firmware
𝑥
< 5.7.21
moxaedr-g902_firmware
𝑥
< 5.7.21
moxaedr-g902-t_firmware
𝑥
< 5.7.21
moxaedr-810-vpn-2gsfp_firmware
𝑥
< 5.12.29
moxaedr-810-vpn-2gsfp-t_firmware
𝑥
< 5.12.29
moxaedr-810-2gsfp_firmware
𝑥
< 5.12.29
moxaedr-810-2gsfp-t_firmware
𝑥
< 5.12.29
𝑥
= Vulnerable software versions