CVE-2019-5153: Critical severity moxa awk-3131a firmware vulnerability
An exploitable remote code execution vulnerability exists in the iwwebs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5153?
CVE-2019-5153 is a remote code execution vulnerability in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13.
How severe is CVE-2019-5153?
CVE-2019-5153 has a severity rating of 8.8 (Critical).
Which software is affected by CVE-2019-5153?
The Moxa AWK-3131A firmware version 1.13 is affected by CVE-2019-5153.
How does CVE-2019-5153 work?
CVE-2019-5153 can be exploited by sending a specially crafted user name entry that causes an overflow of an error message buffer, leading to remote code execution.
Is there a fix for CVE-2019-5153?
It is recommended to update to a patched version of the Moxa AWK-3131A firmware to mitigate the vulnerability.