CVE-2019-5142: OS Command Injection
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-5142?
The severity of CVE-2019-5142 is critical with a CVSS score of 7.2.
How does the command injection vulnerability in CVE-2019-5142 work?
The command injection vulnerability in CVE-2019-5142 allows an attacker to execute arbitrary system commands by exploiting the hostname functionality of the Moxa AWK-3131A firmware version 1.13.
What is the affected software for CVE-2019-5142?
The affected software for CVE-2019-5142 is the Moxa AWK-3131A firmware version 1.13.
How can an attacker exploit CVE-2019-5142?
An attacker can exploit CVE-2019-5142 by crafting a specially designed entry to network configuration information, which triggers the execution of arbitrary system commands and provides full control of the device.
Is the Moxa AWK-3131A device vulnerable to CVE-2019-5142?
Yes, the Moxa AWK-3131A device running firmware version 1.13 is vulnerable to CVE-2019-5142.