CVE-2024-1220

EUVD-2024-16987
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
moxanport_w2150a_firmware
𝑥
≤ 2.3
moxanport_w2250a_firmware
𝑥
≤ 2.3
moxanport_w2150a-t_firmware
𝑥
≤ 2.3
moxanport_w2250a-t_firmware
𝑥
≤ 2.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
moxanport_w2150a_firmware
1.0 ≤
𝑥
≤ 2.3
ADP