First published: Tue Feb 25 2020(Updated: )
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa AWK-3131A firmware | =1.13 | |
Moxa AWK-3131A |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5148 is a denial-of-service vulnerability in the ServiceAgent functionality of the Moxa AWK-3131A firmware version 1.13.
CVE-2019-5148 has a severity rating of 7.5 out of 10, which is considered high.
The affected software in CVE-2019-5148 is the Moxa AWK-3131A firmware version 1.13.
CVE-2019-5148 can be exploited by sending a specially crafted packet that triggers an integer underflow, leading to a denial-of-service condition.
At the time of writing, there is no information available about a fix for CVE-2019-5148. It is recommended to stay updated with the vendor's security advisories for any patches or mitigations.