CVE-2024-9137 is a critical authentication bypass vulnerability (CVSS 9.4) affecting Moxa products, allowing unauthenticated attackers to execute arbitrary commands by sending specially crafted requests to the Moxa service. This flaw enables unauthorized configuration file manipulation (downloads/uploads) and potential system compromise. While no specific affected products are listed, the vulnerability's high severity and network-based attack vector pose a significant risk. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Moxa | EDF-G1002-BP Series | >= 1.0, <= 3.12.1CNA affecteddefault unaffected | |
| Moxa | EDR-8010 Series | >= 1.0, <= 3.12.1CNA affecteddefault unaffected | |
| Moxa | EDR-G9004 Series | >= 1.0, <= 3.12.1CNA affecteddefault unaffected | |
| Moxa | EDR-G9010 Series | >= 1.0, <= 3.12.1CNA affecteddefault unaffected | |
| Moxa | EDS-405A Series | >= 1.0, <= 3.14CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.