CVE-2019-6563: Critical severity moxa iks-g6824a firmware vulnerability
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6563?
CVE-2019-6563 is rated as a high severity vulnerability due to the potential for an attacker to capture an administrator's password.
How do I fix CVE-2019-6563?
To fix CVE-2019-6563, update your Moxa IKS and EDS devices to firmware version higher than 4.5 for IKS-G6824A and 3.8 for the EDS series.
What devices are affected by CVE-2019-6563?
CVE-2019-6563 affects Moxa IKS-G6824A firmware versions up to 4.5 and Moxa EDS-405A, EDS-408A, and EDS-510A firmware versions up to 3.8.
What impact could CVE-2019-6563 have on my network?
Exploitation of CVE-2019-6563 could lead to a total compromise of affected Moxa devices, allowing unauthorized control over network operations.
Is CVE-2019-6563 being actively exploited?
At the time of discovery, there were no confirmed incidents of active exploitation for CVE-2019-6563, but the vulnerability's nature poses serious risks.