7.5
CVE-2019-6518
- EPSS 0.11%
- Veröffentlicht 05.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:36
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Iks-g6824a Firmware Version <= 4.5
Moxa ≫ Eds-405a Firmware Version <= 3.8
Moxa ≫ Eds-408a Firmware Version <= 3.8
Moxa ≫ Eds-510a Firmware Version <= 3.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.295 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-256 Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.