PT-2017-3772 · Moxa · Moxa Eds-408A+3
Published
2017-11-13
·
Updated
2022-11-30
·
CVE-2019-6559
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa EDS-405A versions (affected versions not specified)
Moxa EDS-408A versions (affected versions not specified)
Moxa EDS-510A versions (affected versions not specified)
Moxa IKS versions (affected versions not specified)
Description
The issue is related to an uncontrolled resource consumption in the firmware of Moxa switches. It may allow a remote attacker to cause a denial of service using a specially crafted packet, potentially leading to a crash of the switch.
Recommendations
For Moxa EDS-405A, consider restricting access to the network to minimize the risk of exploitation until a patch is available.
For Moxa EDS-408A, avoid using the switch with untrusted input until the issue is resolved.
For Moxa EDS-510A, consider disabling remote access to the switch until a fix is provided.
For Moxa IKS, restrict access to the switch to authenticated users only as a temporary mitigation measure.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Eds-405A
Moxa Eds-408A
Moxa Eds-510E
Moxa Iks