PT-2020-1756 · Moxa · Moxa Awk-3131A
Jared Rittle
·
Published
2020-02-25
·
Updated
2022-06-13
·
CVE-2019-5153
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3131A firmware version 1.13
Description
The issue is related to a buffer overflow in the iw webs component of the Moxa AWK-3131A firmware. It allows a remote attacker to execute arbitrary code by exploiting the vulnerability in the configuration parsing functionality. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. This can be triggered by an attacker sending commands while authenticated as a low-privilege user.
Recommendations
For Moxa AWK-3131A firmware version 1.13, consider disabling the
iw webs component until a patch is available to prevent exploitation. Restrict access to the configuration parsing functionality to minimize the risk of remote code execution. Avoid using specially crafted user name entries in the affected firmware version until the issue is resolved.Exploit
Fix
Buffer Overflow
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Awk-3131A