Vulnerability Details CVE-2020-28144
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Firmware Version 5.6 or lower. Crafted requests sent to the device may allow remote arbitrary code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-28144
-
cpe:2.3:h:moxa:edr-810-2gsfp-t:-
-
cpe:2.3:h:moxa:edr-810-2gsfp:-
-
cpe:2.3:h:moxa:edr-810-vpn-2gsfp-t:-
-
cpe:2.3:h:moxa:edr-810-vpn-2gsfp:-
-
cpe:2.3:h:moxa:edr-g902-t:-
-
cpe:2.3:h:moxa:edr-g902:-
-
cpe:2.3:h:moxa:edr-g903-t:-
-
cpe:2.3:h:moxa:edr-g903:-
-
cpe:2.3:o:moxa:edr-810-2gsfp-t_firmware:5.6
-
cpe:2.3:o:moxa:edr-810-2gsfp_firmware:5.6
-
cpe:2.3:o:moxa:edr-810-vpn-2gsfp-t_firmware:5.6
-
cpe:2.3:o:moxa:edr-810-vpn-2gsfp_firmware:5.6
-
cpe:2.3:o:moxa:edr-g902-t_firmware:-
-
cpe:2.3:o:moxa:edr-g902-t_firmware:5.4
-
cpe:2.3:o:moxa:edr-g902-t_firmware:5.5
-
cpe:2.3:o:moxa:edr-g902_firmware:-
-
cpe:2.3:o:moxa:edr-g902_firmware:5.4
-
cpe:2.3:o:moxa:edr-g902_firmware:5.5
-
cpe:2.3:o:moxa:edr-g903-t_firmware:-
-
cpe:2.3:o:moxa:edr-g903-t_firmware:5.4
-
cpe:2.3:o:moxa:edr-g903-t_firmware:5.5
-
cpe:2.3:o:moxa:edr-g903_firmware:-
-
cpe:2.3:o:moxa:edr-g903_firmware:1.0
-
cpe:2.3:o:moxa:edr-g903_firmware:2.0
-
cpe:2.3:o:moxa:edr-g903_firmware:2.1
-
cpe:2.3:o:moxa:edr-g903_firmware:2.11
-
cpe:2.3:o:moxa:edr-g903_firmware:2.2
-
cpe:2.3:o:moxa:edr-g903_firmware:3.4.11
-
cpe:2.3:o:moxa:edr-g903_firmware:5.4
-
cpe:2.3:o:moxa:edr-g903_firmware:5.5