First published: Tue Feb 25 2020(Updated: )
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa AWK-3131A firmware | =1.13 | |
Moxa AWK-3131A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-5142 is critical with a CVSS score of 7.2.
The command injection vulnerability in CVE-2019-5142 allows an attacker to execute arbitrary system commands by exploiting the hostname functionality of the Moxa AWK-3131A firmware version 1.13.
The affected software for CVE-2019-5142 is the Moxa AWK-3131A firmware version 1.13.
An attacker can exploit CVE-2019-5142 by crafting a specially designed entry to network configuration information, which triggers the execution of arbitrary system commands and provides full control of the device.
Yes, the Moxa AWK-3131A device running firmware version 1.13 is vulnerable to CVE-2019-5142.