CVE-2019-5165: High severity moxa awk-3131a firmware vulnerability
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5165?
CVE-2019-5165 is an exploitable authentication bypass vulnerability in the Moxa AWK-3131A firmware version 1.13.
What is the severity of CVE-2019-5165?
CVE-2019-5165 has a severity rating of high (7.2).
How does CVE-2019-5165 work?
CVE-2019-5165 allows an attacker to bypass web authentication by using a specially configured device hostname.
Which software versions are affected by CVE-2019-5165?
CVE-2019-5165 affects Moxa AWK-3131A firmware version 1.13.
How can I fix CVE-2019-5165?
To fix CVE-2019-5165, users should update their Moxa AWK-3131A firmware to a secure version.