CVE-2019-5148: Integer Underflow
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5148?
CVE-2019-5148 is a denial-of-service vulnerability in the ServiceAgent functionality of the Moxa AWK-3131A firmware version 1.13.
How severe is CVE-2019-5148?
CVE-2019-5148 has a severity rating of 7.5 out of 10, which is considered high.
What is the affected software in CVE-2019-5148?
The affected software in CVE-2019-5148 is the Moxa AWK-3131A firmware version 1.13.
How can CVE-2019-5148 be exploited?
CVE-2019-5148 can be exploited by sending a specially crafted packet that triggers an integer underflow, leading to a denial-of-service condition.
Is there a fix available for CVE-2019-5148?
At the time of writing, there is no information available about a fix for CVE-2019-5148. It is recommended to stay updated with the vendor's security advisories for any patches or mitigations.