9.8
CVE-2019-6524
- EPSS 0.25%
- Veröffentlicht 05.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:46:37
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Iks-g6824a Firmware Version <= 4.5
Moxa ≫ Eds-405a Firmware Version <= 3.8
Moxa ≫ Eds-408a Firmware Version <= 3.8
Moxa ≫ Eds-510a Firmware Version <= 3.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.479 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.