cbcvebase.
CVE-2024-1220
published 2024-03-06

CVE-2024-1220: A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.66%
47.3th percentile
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

Affected

17 ranges
VendorProductVersion rangeFixed in
aimeosai-admin-graphql>= 2022.04.1 < 2022.10.102022.10.10
aimeosai-admin-graphql>= 2023.04.1 < 2023.10.62023.10.6
aimeosai-admin-graphql>= 2024.04.1 < 2024.04.62024.04.6
aimeosai-admin-graphql>= 2024.04.1 < 2024.04.22024.04.2
gitlabgitlab
gitlabgitlab_ce
kimaikimai>= 0 < 2.13.02.13.0
lunarylunary>= 0 < 1.4.91.4.9
lunarylunary>= 0 < 1.4.101.4.10
moxanport_w2150a-t_firmware<= 2.3
moxanport_w2150a_firmware<= 2.3
moxanport_w2150a_w2250a_series1.0 – 2.3
moxanport_w2250a-t_firmware<= 2.3
moxanport_w2250a_firmware<= 2.3
msrcmicrosoft_edge_for_android
msrcmicrosoft_outlook_for_android
zenmlzenml>= 0 < 0.56.20.56.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
vendor_msrc5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.