PT-2020-1757 · Moxa · Moxa Awk-3131A

Published

2020-02-25

·

Updated

2022-06-13

·

CVE-2019-5162

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moxa AWK-3131A firmware version 1.13
Description An exploitable improper access control issue exists in the iw webs account settings functionality. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this issue.
Recommendations For Moxa AWK-3131A firmware version 1.13, consider disabling the iw webs account settings functionality until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of remote shell access. Avoid using specially crafted user name entries in the account settings to prevent overwriting existing user account passwords.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00997
CVE-2019-5162

Affected Products

Moxa Awk-3131A