CVE-2024-9404
published 2024-12-04CVE-2024-9404: This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.76%
51.1th percentile
This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If exposed to public networks, the vulnerability poses a significant remote threat, potentially allowing attackers to shut down affected systems.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | eds-405a_series | 1.0 – 3.14 | — |
| moxa | eds-408a_series | 1.0 – 3.12 | — |
| moxa | eds-505a_series | 1.0 – 3.11 | — |
| moxa | eds-508a_series | 1.0 – 3.11 | — |
| moxa | eds-510a_series | 1.0 – 3.12 | — |
| moxa | eds-510e_series | 1.0 – 5.5 | — |
| moxa | eds-516a_series | 1.0 – 3.11 | — |
| moxa | eds-518a_series | 1.0 – 3.11 | — |
| moxa | eds-518e_series | 1.0 – 6.3 | — |
| moxa | eds-528e_series | 1.0 – 6.3 | — |
| moxa | eds-608_series | 1.0 – 3.12 | — |
| moxa | eds-611_series | 1.0 – 3.12 | — |
| moxa | eds-616_series | 1.0 – 3.12 | — |
| moxa | eds-619_series | 1.0 – 3.12 | — |
| moxa | eds-g508e_series | 1.0 – 6.4 | — |
| moxa | eds-g509_series | 1.0 – 3.10 | — |
| moxa | eds-g512e_series | 1.0 – 6.4 | — |
| moxa | eds-g516e_series | 1.0 – 6.4 | — |
| moxa | eds-p506e_series | 1.0 – 5.8 | — |
| moxa | eds-p510_series | 1.0 – 3.11 | — |
| moxa | eds-p510a_series | 1.0 – 3.11 | — |
| moxa | ics-g7526a_series | 1.0 – 5.10 | — |
| moxa | ics-g7528a_series | 1.0 – 5.10 | — |
| moxa | ics-g7748a_series | 1.0 – 5.9 | — |
| moxa | ics-g7750a_series | 1.0 – 5.9 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-240930-cve-2024-9404-denial-of-service-vulnerability-identified-in-the-vport-07-3-serieshttps://www.moxa.com/en/support/product-support/security-advisory/mpsa-240931-cve-2024-9404-denial-of-service-vulnerability-identified-in-multiple-eds,-ics,-iks,-and-sds-switcheshttps://www.moxa.com/en/support/product-support/security-advisory/mpsa-240933-cve-2024-9404-denial-of-service-vulnerability-identified-in-multiple-pt-switches
2024-12-04
Published