PT-2020-1756 · Moxa · Moxa Awk-3131A

Jared Rittle

·

Published

2020-02-25

·

Updated

2022-06-13

·

CVE-2019-5153

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa AWK-3131A firmware version 1.13
Description The issue is related to a buffer overflow in the iw webs component of the Moxa AWK-3131A firmware. It allows a remote attacker to execute arbitrary code by exploiting the vulnerability in the configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. This can be triggered by an attacker sending commands while authenticated as a low-privilege user.
Recommendations For Moxa AWK-3131A firmware version 1.13, consider disabling the iw webs component until a patch is available to prevent exploitation. Restrict access to the configuration parsing functionality to minimize the risk of remote code execution. Avoid using specially crafted user name entries in the affected firmware version until the issue is resolved.

Exploit

Fix

Buffer Overflow

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00996
CVE-2019-5153

Affected Products

Moxa Awk-3131A