PT-2018-2602 · Moxa · Moxa Eds+2

Published

2018-04-19

·

Updated

2022-11-30

·

CVE-2019-6557

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa IKS and EDS (affected versions not specified) Moxa IKS-G6824A (affected versions not specified)
Description The issue is related to buffer overflow vulnerabilities in Moxa IKS and EDS, which may allow remote code execution. Specifically, the vulnerability in Moxa IKS-G6824A is due to a lack of size check for input data during buffer copying, allowing a remote attacker to execute arbitrary code.
Recommendations For Moxa IKS and EDS, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Moxa IKS-G6824A, consider restricting access to the device until a patch is available to minimize the risk of exploitation.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2019-01117
CVE-2019-6557

Affected Products

Moxa Eds
Moxa Iks
Moxa Iks-G6824A