CVE-2019-5137: High severity moxa awk-3131a firmware vulnerability
Published Feb 25, 2020
·Updated
The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.
Affected Software
2 affected components
MOXA AWK-3131A firmware=1.13
MOXA AWK-3131A
Event History
Feb 25, 2020
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-5137.
2
What is the severity of CVE-2019-5137?
The severity of CVE-2019-5137 is high with a severity value of 7.5.
3
What does CVE-2019-5137 allow?
CVE-2019-5137 allows for the decryption of captured network traffic.
4
Which software version is affected by CVE-2019-5137?
The Moxa AWK-3131A firmware version 1.13 is affected by CVE-2019-5137.
5
How can I fix CVE-2019-5137?
To fix CVE-2019-5137, it is recommended to update the Moxa AWK-3131A firmware to a version that addresses this vulnerability.