Lucene search

K
cveIcscertCVE-2015-6464
HistorySep 11, 2015 - 4:59 p.m.

CVE-2015-6464

2015-09-1116:59:07
icscert
web.nvd.nist.gov
26
moxa
eds-405a
eds-408a
firmware
bypass
read-only
protection
web interface
cve-2015-6464
nvd

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

54.0%

The administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-only protection mechanism by using Firefox with a web-developer plugin.

Affected configurations

Nvd
Node
moxaeds-405a_firmwareRange3.4
OR
moxaeds-408a_firmwareRange3.4
AND
moxaeds-405aMatch-
OR
moxaeds-408aMatch-
VendorProductVersionCPE
moxaeds-405a_firmware*cpe:2.3:o:moxa:eds-405a_firmware:*:*:*:*:*:*:*:*
moxaeds-408a_firmware*cpe:2.3:o:moxa:eds-408a_firmware:*:*:*:*:*:*:*:*
moxaeds-405a-cpe:2.3:h:moxa:eds-405a:-:*:*:*:*:*:*:*
moxaeds-408a-cpe:2.3:h:moxa:eds-408a:-:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:C/A:C

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

54.0%

Related for CVE-2015-6464