CVE-2019-5143: High severity moxa awk-3131a firmware vulnerability
An exploitable format string vulnerability exists in the iwconsole coniowritestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5143?
CVE-2019-5143 is a format string vulnerability found in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13.
How severe is CVE-2019-5143?
CVE-2019-5143 has a severity rating of 8.8, which is considered high.
How does CVE-2019-5143 affect Moxa AWK-3131A firmware version 1.13?
CVE-2019-5143 can result in remote code execution due to an overflow of the time server buffer.
Is Moxa AWK-3131A firmware version 1.13 the only affected software?
Yes, Moxa AWK-3131A firmware version 1.13 is the only affected software.
How can I fix CVE-2019-5143?
To fix CVE-2019-5143, it is recommended to update to a patched version of the Moxa AWK-3131A firmware.