CVE-2019-6522
Summary
| CVE | CVE-2019-6522 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-05 20:29:00 UTC |
| Updated | 2022-11-30 22:21:00 UTC |
| Description | Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Moxa | Eds-405a | - | All | All | All |
| Hardware | Moxa | Eds-405a | - | All | All | All |
| Operating System | Moxa | Eds-405a Firmware | All | All | All | All |
| Hardware | Moxa | Eds-408a | - | All | All | All |
| Hardware | Moxa | Eds-408a | - | All | All | All |
| Operating System | Moxa | Eds-408a Firmware | All | All | All | All |
| Hardware | Moxa | Eds-510a | - | All | All | All |
| Hardware | Moxa | Eds-510a | - | All | All | All |
| Operating System | Moxa | Eds-510a Firmware | All | All | All | All |
| Hardware | Moxa | Iks-g6824a | - | All | All | All |
| Hardware | Moxa | Iks-g6824a | - | All | All | All |
| Operating System | Moxa | Iks-g6824a Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Moxa IKS, EDS (Update A) | CISA | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| Moxa IKS and EDS ICSA-19-057-01 Multiple Security Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.