First published: Wed Feb 03 2021(Updated: )
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa EDR-G903 Firmware | <=5.5 | |
Moxa EDR-G903 Firmware | ||
Moxa EDR-G903 Firmware | <=5.5 | |
Moxa EDR-G903-T Firmware | ||
Moxa EDR-G902 Series | <=5.5 | |
Moxa EDR-G902 Series | ||
Moxa EDR-G902-T Firmware | <=5.5 | |
Moxa EDR-G902-T Firmware | ||
Moxa EDR-810 Firmware | <=5.6 | |
Moxa EDR-810 | ||
Moxa EDR-810 Firmware | <=5.6 | |
Moxa EDR-810 Firmware | ||
Moxa EDR-810 VPN 2G-SFP Firmware | <=5.6 | |
Moxa Edr-810-vpn-2gsfp Firmware | ||
Moxa Edr-810-vpn-2gsfp Firmware | <=5.6 | |
Moxa EDR-810 VPN 2G-SFP-T |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28144 is a vulnerability that affects certain Moxa Inc products running EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower.
CVE-2020-28144 has a severity rating of 9.8 (critical).
CVE-2020-28144 can be exploited by sending crafted requests to the affected device, allowing remote arbitrary code execution.
Moxa EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower are affected by CVE-2020-28144.
To fix CVE-2020-28144, update the firmware of the affected Moxa Inc products to a version higher than the vulnerable versions listed (5.5 for EDR-G903 and EDR-G902, 5.6 for EDR-810).