CVE-2024-1220

HIGH

Moxa NPort W2150A/W2250A Series Firmware < 2.3 - Denial of Service via Web Server Stack-Based Buffer Overflow

Title source: llm
STIX 2.1

Description

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.

Scores

CVSS v3 8.2
EPSS 0.0152
EPSS Percentile 81.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-121 CWE-787
Status published
Products (4)
moxa/nport_w2150a-t_firmware < 2.3
moxa/nport_w2150a_firmware < 2.3
moxa/nport_w2250a-t_firmware < 2.3
moxa/nport_w2250a_firmware < 2.3
Published Mar 06, 2024
Tracked Since Feb 18, 2026