PT-2017-3772 · Moxa · Moxa Eds-408A+3

Published

2017-11-13

·

Updated

2022-11-30

·

CVE-2019-6559

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Moxa EDS-405A versions (affected versions not specified) Moxa EDS-408A versions (affected versions not specified) Moxa EDS-510A versions (affected versions not specified) Moxa IKS versions (affected versions not specified)
Description The issue is related to an uncontrolled resource consumption in the firmware of Moxa switches. It may allow a remote attacker to cause a denial of service using a specially crafted packet, potentially leading to a crash of the switch.
Recommendations For Moxa EDS-405A, consider restricting access to the network to minimize the risk of exploitation until a patch is available. For Moxa EDS-408A, avoid using the switch with untrusted input until the issue is resolved. For Moxa EDS-510A, consider disabling remote access to the switch until a fix is provided. For Moxa IKS, restrict access to the switch to authenticated users only as a temporary mitigation measure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2019-01122
CVE-2019-6559

Affected Products

Moxa Eds-405A
Moxa Eds-408A
Moxa Eds-510E
Moxa Iks