PT-2020-1757 · Moxa · Moxa Awk-3131A
Published
2020-02-25
·
Updated
2022-06-13
·
CVE-2019-5162
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moxa AWK-3131A firmware version 1.13
Description
An exploitable improper access control issue exists in the iw webs account settings functionality. A specially crafted
user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this issue.Recommendations
For Moxa AWK-3131A firmware version 1.13, consider disabling the
iw webs account settings functionality until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of remote shell access. Avoid using specially crafted user name entries in the account settings to prevent overwriting existing user account passwords.Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moxa Awk-3131A