CVE-2019-6520

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/03/2019
Last modified:
19/10/2020

Description

Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:iks-g6824a_firmware:*:*:*:*:*:*:*:* 4.5 (including)
cpe:2.3:h:moxa:iks-g6824a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:eds-405a_firmware:*:*:*:*:*:*:*:* 3.8 (including)
cpe:2.3:h:moxa:eds-405a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:eds-408a_firmware:*:*:*:*:*:*:*:* 3.8 (including)
cpe:2.3:h:moxa:eds-408a:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:eds-510a_firmware:*:*:*:*:*:*:*:* 3.8 (including)
cpe:2.3:h:moxa:eds-510a:-:*:*:*:*:*:*:*