Логотип exploitDog
bind:CVE-2019-5162
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-5162

Количество 3

Количество 3

nvd логотип

CVE-2019-5162

почти 6 лет назад

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-536j-cvcw-6cqq

больше 3 лет назад

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2020-00997

почти 6 лет назад

Уязвимость в настройках учетной записи iw_webs микропрограммного обеспечения беспроводной точки доступа для промышленных систем Moxa AWK-3131A, позволяющая нарушителю перезаписать пароль учетной записи пользователя

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-5162

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
почти 6 лет назад
github логотип
GHSA-536j-cvcw-6cqq

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2020-00997

Уязвимость в настройках учетной записи iw_webs микропрограммного обеспечения беспроводной точки доступа для промышленных систем Moxa AWK-3131A, позволяющая нарушителю перезаписать пароль учетной записи пользователя

CVSS3: 8.8
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу