CVE-2024-9139

Severity
8.6HIGH
EPSS
0.3%
top 49.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages8 packages

CVEListV5moxa/edr-810_series1.05.12.33
CVEListV5moxa/nat-102_series1.01.0.5
CVEListV5moxa/tn-4900_series1.03.6
CVEListV5moxa/edr-8010_series1.03.12.1
CVEListV5moxa/edr-g9004_series1.03.12.1

🔴Vulnerability Details

2
GHSA
GHSA-6vmr-rjpc-xf64: The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code2024-10-14
CVEList
OS Command Injection in Restricted Command2024-10-14