CVE-2019-6518: High severity MOXA Iks-g6824a Firmware vulnerability
Published Mar 5, 2019
·Updated
Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.
Affected Software
16 affected components
All of the following
MOXA Iks-g6824a Firmware<=4.5
MOXA IKS-G6824A
All of the following
MOXA Eds-405a Firmware<=3.8
MOXA EDS-405A
All of the following
MOXA Eds-408a Firmware<=3.8
MOXA EDS-408A
All of the following
MOXA Eds-510a Firmware<=3.8
MOXA EDS-510A
MOXA Iks-g6824a Firmware<=4.5
MOXA IKS-G6824A
MOXA Eds-405a Firmware<=3.8
MOXA EDS-405A
MOXA Eds-408a Firmware<=3.8
MOXA EDS-408A
MOXA Eds-510a Firmware<=3.8
MOXA EDS-510A
Event History
Mar 5, 2019
CVE Published
via NVD·08:29 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-6518?
CVE-2019-6518 has a medium severity level due to the risk of sensitive information exposure.
2
How do I fix CVE-2019-6518?
To mitigate CVE-2019-6518, update the Moxa devices to firmware versions that secure plaintext passwords.
3
What devices are affected by CVE-2019-6518?
CVE-2019-6518 affects Moxa IKS products with firmware versions up to 4.5 and EDS products with firmware versions up to 3.8.
4
Is CVE-2019-6518 a critical vulnerability?
CVE-2019-6518 is not classified as critical but does present a risk to device security.
5
Can CVE-2019-6518 lead to unauthorized access?
Yes, CVE-2019-6518 may facilitate unauthorized access to sensitive information due to the storage of plaintext passwords.