CVE-2019-5136: Critical severity moxa awk-3131a firmware vulnerability
An exploitable privilege escalation vulnerability exists in the iwconsole functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5136?
CVE-2019-5136 is an exploitable privilege escalation vulnerability in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13.
What is the severity of CVE-2019-5136?
CVE-2019-5136 has a severity score of 8.8, which is classified as critical.
How does CVE-2019-5136 work?
CVE-2019-5136 can be exploited by sending a specially crafted menu selection string to the iw_console functionality, allowing an attacker to escape the restricted console and gain system access as the root user.
Is the Moxa AWK-3131A firmware version 1.13 vulnerable to CVE-2019-5136?
Yes, the Moxa AWK-3131A firmware version 1.13 is vulnerable to CVE-2019-5136.
How can I fix CVE-2019-5136?
To fix CVE-2019-5136, it is recommended to update the Moxa AWK-3131A firmware to a version that addresses the vulnerability.