First published: Wed Nov 01 2023(Updated: )
A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.
Credit: psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Moxa EDR-G903 Firmware | <5.7.21 | |
Moxa EDR-G903 Firmware | ||
All of | ||
Moxa EDR-G903 Firmware | <5.7.21 | |
Moxa EDR-G903-T Firmware | ||
All of | ||
Moxa EDR-G902 Series | <5.7.21 | |
Moxa EDR-G902 Series | ||
All of | ||
Moxa EDR-G902-T Firmware | <5.7.21 | |
Moxa EDR-G902-T Firmware | ||
All of | ||
Moxa EDR-810 VPN 2G-SFP Firmware | <5.12.29 | |
Moxa Edr-810-vpn-2gsfp Firmware | ||
All of | ||
Moxa Edr-810-vpn-2gsfp Firmware | <5.12.29 | |
Moxa EDR-810 VPN 2G-SFP-T | ||
All of | ||
Moxa EDR-810 Firmware | <5.12.29 | |
Moxa EDR-810 | ||
All of | ||
Moxa EDR-810 Firmware | <5.12.29 | |
Moxa EDR-810 Firmware |
Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * EDR-810 Series: Please upgrade to firmware v5.12.29 or later * EDR-G902 Series: Please upgrade to firmware v5.7.21 or later * EDR-G903 Series: Please upgrade to firmware v5.7.21 or later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-4452.
The severity of CVE-2023-4452 is high with a severity value of 7.5.
The EDR-810, EDR-G902, and EDR-G903 Series with firmware versions up to exclusive 5.7.21 are affected by CVE-2023-4452.
CVE-2023-4452 allows malicious users to trigger a denial-of-service vulnerability in the affected devices by exploiting insufficient input validation in the URI, potentially causing the devices to reboot.
To fix CVE-2023-4452, it is recommended to update the firmware of the affected devices to a version that is not vulnerable.