logo

Stack-Based Buffer Overflow Vulnerability Discovered in Industrial VPN

ID: 9b2a5cef-45ab-51b3-b73a-fb2839d0f8e7

STIX ID: report--9b2a5cef-45ab-51b3-b73a-fb2839d0f8e7

Feed Name: Claroty Team82

Threat Score
78/100

Date Published: 2023-10-18

Date Updated: 2026-04-17

...
...

Claroty and CISA disclosed a critical stack-based buffer overflow (CVE-2020-14511, CVSS 9.8) in Moxa EDR-G902/EDR-G903 industrial VPN routers (versions ≤ 5.4) that allows an unauthenticated attacker to trigger remote code execution via an oversized HTTP cookie; devices commonly exposed to the internet and used in critical infrastructure should be updated with vendor firmware patches or isolated/ protected per CISA guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.