Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gj6-9934-w9r6

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service.

This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

Moxa’s IP Cameras are affected by a medium-severity vulnerability, CVE-2024-9404, which could lead to a denial-of-service condition or cause a service crash. This vulnerability allows attackers to exploit the Moxa service, commonly referred to as moxa_cmd, originally designed for deployment. Because of insufficient input validation, this service may be manipulated to trigger a denial-of-service.

This vulnerability poses a significant remote threat if the affected products are exposed to publicly accessible networks. Attackers could potentially disrupt operations by shutting down the affected systems. Due to the critical nature of this security risk, we strongly recommend taking immediate action to prevent potential exploitation.

EPSS

Процентиль: 19%
0.00062
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-1287

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability poses a significant remote threat, potentially allowing attackers to shut down affected systems.

CVSS3: 5.3
fstec
около 1 года назад

Уязвимость микропрограммного обеспечения IP-камер Moxa VPORT 07-3, связанная с недостаточной защитой конфиденциальных данных от поставщиков (OSAT), позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00062
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-1287