PT-2019-4577 · Moxa · Moxa Awk-3121
Samuel Huntley
·
Published
2019-06-07
·
Updated
2019-12-05
·
CVE-2018-10703
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3121 version 1.14
Description
An issue was discovered that allows an attacker to execute commands on the device. The
iw serverip parameter is susceptible to buffer overflow, which can be exploited by crafting a packet with a string of 480 characters. This vulnerability may allow a remote attacker to execute arbitrary commands with root privileges.Recommendations
For Moxa AWK-3121 version 1.14, consider disabling the functionality that allows running scripts on the device until a patch is available. Restrict access to the
iw serverip parameter to minimize the risk of exploitation. Avoid using the iw serverip parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Awk-3121