CVE-2019-6565: XSS
Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability to perform XSS attacks, which may be used to send a malicious script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6565?
CVE-2019-6565 is classified as a high severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2019-6565?
To fix CVE-2019-6565, ensure that you update the affected Moxa firmware to a version that has addressed the input validation issues.
Which Moxa products are affected by CVE-2019-6565?
CVE-2019-6565 affects Moxa IKS-G6824A firmware versions up to and including 4.5 as well as EDS-405A, EDS-408A, and EDS-510A firmware versions up to and including 3.8.
What type of attack could be executed due to CVE-2019-6565?
CVE-2019-6565 allows for cross-site scripting (XSS) attacks, enabling attackers to execute malicious scripts on the affected Moxa devices.
Who can exploit CVE-2019-6565?
Both unauthenticated and authenticated attackers can exploit CVE-2019-6565 to perform XSS attacks.