CVE-2015-6465: Medium severity moxa eds-405a firmware vulnerability
Published Sep 11, 2015
·Updated
The GoAhead web server on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to cause a denial of service (reboot) via a crafted URL.
Affected Software
4 affected components
MOXA Eds-405a Firmware<=3.4
MOXA Eds-408a Firmware<=3.4
MOXA EDS-405A
MOXA EDS-408A
Remediation
Event History
Sep 11, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6465?
CVE-2015-6465 is classified as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-6465?
To mitigate CVE-2015-6465, upgrade the firmware of Moxa EDS-405A and EDS-408A switches to version 3.6 or higher.
3
Who is affected by CVE-2015-6465?
CVE-2015-6465 affects Moxa EDS-405A and EDS-408A switches running firmware versions prior to 3.6.
4
What type of attack is CVE-2015-6465 associated with?
CVE-2015-6465 is associated with a remote denial of service attack that can be triggered by a crafted URL.
5
Can CVE-2015-6465 be exploited by unauthenticated users?
No, CVE-2015-6465 requires authentication, meaning only remote authenticated users can exploit this vulnerability.