CVE-2020-14511: Buffer Overflow
Published Jul 15, 2020
·Updated
Malicious operation of the crafted web browser cookie may cause a stack-based buffer overflow in the system web server on the EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4).
Affected Software
10 affected components
MOXA EDR-G902 Series: firmware versions 5.4 and prior
MOXA EDR-G903 Series: firmware versions 5.4 and prior
MOXA Edr-g902-t Firmware<=5.4
MOXA Edr-g902-t
MOXA Edr-g902 Firmware<=5.4
MOXA EDR-G902
MOXA Edr-g903-t Firmware<=5.4
MOXA Edr-g903-t
MOXA Edr-g903 Firmware<=5.4
MOXA EDR-G903
Event History
Jul 15, 2020
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
DescriptionWeakness
Aug 4, 2024
Data Sourced
via ICS·12:56 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-14511.
2
What is the severity level of CVE-2020-14511?
The severity level of CVE-2020-14511 is critical (9.8).
3
Which routers are affected by CVE-2020-14511?
The EDR-G902 and EDR-G903 Series Routers (versions prior to 5.4) are affected by CVE-2020-14511.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by performing a malicious operation with a crafted web browser cookie, causing a stack-based buffer overflow in the system web server.
5
Is there a fix available for CVE-2020-14511?
Yes, updating the firmware to version 5.4 or higher resolves the vulnerability.