CVE-2019-5165
- EPSS 0.15%
- Veröffentlicht 25.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:28
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulti...
- EPSS 0.52%
- Veröffentlicht 25.02.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:28
An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, r...
CVE-2019-5153
- EPSS 2.27%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:27
An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting ...
CVE-2019-5148
- EPSS 0.71%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:26
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of...
CVE-2019-5143
- EPSS 3.06%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote c...
- EPSS 2.21%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resultin...
CVE-2019-5141
- EPSS 5.75%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting i...
CVE-2019-5140
- EPSS 1.98%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulti...
CVE-2019-5139
- EPSS 0.13%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom di...
CVE-2019-5138
- EPSS 3.71%
- Veröffentlicht 25.02.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:44:25
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting ...