CVE-2019-6524
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 4.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Iks G6824a | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.8 |
| Running on/with | Platform Versions |
|---|---|
Moxa Eds 405a | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.8 |
| Running on/with | Platform Versions |
|---|---|
Moxa Eds 408a | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.8 |
| Running on/with | Platform Versions |
|---|---|
Moxa Eds 510a | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.