← Back to CVEs
CVE-2019-5142
HIGH7.2
Description
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.
CVE Details
CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published2/25/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
moxa:awk-3131amoxa:awk-3131a_firmware
Weaknesses (CWE)
CWE-78CWE-78
References
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0931(talos-cna@cisco.com)
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0931(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.