Lucene search

K
nvd[email protected]NVD:CVE-2019-6522
HistoryMar 05, 2019 - 8:29 p.m.

CVE-2019-6522

2019-03-0520:29:00
CWE-125
web.nvd.nist.gov
2

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

51.1%

Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot.

Affected configurations

Nvd
Node
moxaiks-g6824a_firmwareRange4.5
AND
moxaiks-g6824aMatch-
Node
moxaeds-405a_firmwareRange3.8
AND
moxaeds-405aMatch-
Node
moxaeds-408a_firmwareRange3.8
AND
moxaeds-408aMatch-
Node
moxaeds-510a_firmwareRange3.8
AND
moxaeds-510aMatch-
VendorProductVersionCPE
moxaiks-g6824a_firmware*cpe:2.3:o:moxa:iks-g6824a_firmware:*:*:*:*:*:*:*:*
moxaiks-g6824a-cpe:2.3:h:moxa:iks-g6824a:-:*:*:*:*:*:*:*
moxaeds-405a_firmware*cpe:2.3:o:moxa:eds-405a_firmware:*:*:*:*:*:*:*:*
moxaeds-405a-cpe:2.3:h:moxa:eds-405a:-:*:*:*:*:*:*:*
moxaeds-408a_firmware*cpe:2.3:o:moxa:eds-408a_firmware:*:*:*:*:*:*:*:*
moxaeds-408a-cpe:2.3:h:moxa:eds-408a:-:*:*:*:*:*:*:*
moxaeds-510a_firmware*cpe:2.3:o:moxa:eds-510a_firmware:*:*:*:*:*:*:*:*
moxaeds-510a-cpe:2.3:h:moxa:eds-510a:-:*:*:*:*:*:*:*

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:P/I:N/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

AI Score

9.3

Confidence

High

EPSS

0.001

Percentile

51.1%

Related for NVD:CVE-2019-6522