CVE-2017-14438: Input Validation
Published May 14, 2018
·Updated
Exploitable denial of service vulnerabilities exists in the Service Agent functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted packet can cause a denial of service. An attacker can send a large packet to 4000/tcp to trigger this vulnerability.
Affected Software
2 affected components
MOXA Edr-810 Firmware=4.1
MOXA EDR-810
Event History
May 14, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14438?
CVE-2017-14438 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-14438?
To mitigate CVE-2017-14438, update the Moxa EDR-810 firmware to a version beyond 4.1.
3
What causes CVE-2017-14438?
CVE-2017-14438 is caused by the Service Agent functionality being vulnerable to specially crafted packets.
4
Which devices are affected by CVE-2017-14438?
CVE-2017-14438 affects the Moxa EDR-810 with firmware version 4.1.
5
Can CVE-2017-14438 be exploited remotely?
Yes, an attacker can exploit CVE-2017-14438 remotely by sending a large crafted packet to port 4000.