First published: Tue Feb 25 2020(Updated: )
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa AWK-3131A firmware | =1.13 | |
Moxa AWK-3131A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5139 is a vulnerability that exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13, allowing for the creation of custom diagnostic scripts using hard-coded credentials.
CVE-2019-5139 has a severity rating of high with a CVSS score of 7.1.
CVE-2019-5139 affects Moxa AWK-3131A firmware version 1.13 and allows attackers to exploit hard-coded credentials to create custom diagnostic scripts.
Yes, Moxa AWK-3131A firmware version 1.13 is vulnerable to the CVE-2019-5139 vulnerability.
To fix the CVE-2019-5139 vulnerability, it is recommended to update the Moxa AWK-3131A firmware to a version that addresses the issue.