CVE-2019-6520: High severity moxa iks-g6824a firmware vulnerability
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6520?
CVE-2019-6520 is classified as a moderate severity vulnerability due to improper authorization checks.
How do I fix CVE-2019-6520?
To fix CVE-2019-6520, update your Moxa IKS and EDS devices to the latest firmware version beyond 4.5 for IKS and 3.8 for EDS firmware.
What devices are affected by CVE-2019-6520?
CVE-2019-6520 affects Moxa IKS-G6824A firmware versions up to 4.5 and Moxa EDS-405A, EDS-408A, and EDS-510A firmware versions up to 3.8.
Can a read-only user exploit CVE-2019-6520?
Yes, a read-only user can exploit CVE-2019-6520 to make arbitrary configuration changes due to insufficient authorization checks.
What can happen if CVE-2019-6520 is exploited?
Exploitation of CVE-2019-6520 may allow unauthorized users to modify device configurations, potentially leading to operational disruptions.