Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-16183 | The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests. | 
Solution
Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * EDS-4000/G4000 Series: Please contact Moxa Technical Support for the security patch (v3.2.26).
Workaround
No workaround given by the vendor.
Tue, 25 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Moxa Moxa eds-4008 Moxa eds-4008 Firmware Moxa eds-4009 Moxa eds-4009 Firmware Moxa eds-4012 Moxa eds-4012 Firmware Moxa eds-4014 Moxa eds-4014 Firmware Moxa eds-g4008 Moxa eds-g4008 Firmware Moxa eds-g4012 Moxa eds-g4012 Firmware Moxa eds-g4014 Moxa eds-g4014 Firmware | |
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:moxa:eds-4008:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-4009:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-4012:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-4014:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-g4008:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-g4012:-:*:*:*:*:*:*:* cpe:2.3:h:moxa:eds-g4014:-:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-4008_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-4009_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-4012_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-4014_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-g4008_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-g4012_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:moxa:eds-g4014_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Moxa Moxa eds-4008 Moxa eds-4008 Firmware Moxa eds-4009 Moxa eds-4009 Firmware Moxa eds-4012 Moxa eds-4012 Firmware Moxa eds-4014 Moxa eds-4014 Firmware Moxa eds-g4008 Moxa eds-g4008 Firmware Moxa eds-g4012 Moxa eds-g4012 Firmware Moxa eds-g4014 Moxa eds-g4014 Firmware | 
Mon, 28 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-441 | 
Mon, 28 Oct 2024 07:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 28 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests. | The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the product and have it forwarded to the target. An attacker can bypass access controls or hide the source of malicious requests. | 
| Weaknesses | CWE-1188 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2024-10-28T06:15:50.712Z
Reserved: 2024-01-10T00:03:24.382Z
Link: CVE-2024-0387
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-01T18:04:49.469Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-02-26T16:27:49.890
Modified: 2025-02-25T22:56:10.743
Link: CVE-2024-0387
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.