CVE-2024-1220

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit the vulnerability by sending crafted payload to the web service. Successful exploitation of the vulnerability could result in denial of service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:moxa:nport_w2150a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2150a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:moxa:nport_w2250a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2250a:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:moxa:nport_w2150a-t_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2150a-t:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:moxa:nport_w2250a-t_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2250a-t:-:*:*:*:*:*:*:*

History

25 Feb 2025, 17:42

Type Values Removed Values Added
References () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-238975-nport-w2150a-w2250a-series-web-server-stack-based-buffer-overflow-vulnerability - () https://www.moxa.com/en/support/product-support/security-advisory/mpsa-238975-nport-w2150a-w2250a-series-web-server-stack-based-buffer-overflow-vulnerability - Vendor Advisory
CWE CWE-787
CPE cpe:2.3:h:moxa:nport_w2150a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_w2250a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2150a-t:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_w2150a-t_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_w2250a-t_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2250a-t:-:*:*:*:*:*:*:*
cpe:2.3:h:moxa:nport_w2250a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:nport_w2150a_firmware:*:*:*:*:*:*:*:*
First Time Moxa nport W2250a-t Firmware
Moxa nport W2150a-t Firmware
Moxa
Moxa nport W2150a-t
Moxa nport W2250a Firmware
Moxa nport W2150a Firmware
Moxa nport W2250a
Moxa nport W2250a-t
Moxa nport W2150a

Information

Published : 2024-03-06 02:15

Updated : 2025-02-25 17:42


NVD link : CVE-2024-1220

Mitre link : CVE-2024-1220

CVE.ORG link : CVE-2024-1220


JSON object : View

Products Affected

moxa

  • nport_w2250a-t
  • nport_w2150a
  • nport_w2250a_firmware
  • nport_w2250a
  • nport_w2150a-t_firmware
  • nport_w2150a_firmware
  • nport_w2150a-t
  • nport_w2250a-t_firmware
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write