CVE-2024-1220
HIGHMoxa NPort W2150A/W2250A Series Firmware < 2.3 - Denial of Service via Web Server Stack-Based Buffer Overflow
Title source: llmDescription
A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.
References (1)
Core 1
Core References
Scores
CVSS v3
8.2
EPSS
0.0152
EPSS Percentile
81.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-121
CWE-787
Status
published
Products (4)
moxa/nport_w2150a-t_firmware
< 2.3
moxa/nport_w2150a_firmware
< 2.3
moxa/nport_w2250a-t_firmware
< 2.3
moxa/nport_w2250a_firmware
< 2.3
Published
Mar 06, 2024
Tracked Since
Feb 18, 2026