{"api_version":"1","generated_at":"2026-07-23T12:30:18+00:00","cve":"CVE-2019-10963","urls":{"html":"https://cve.report/CVE-2019-10963","api":"https://cve.report/api/cve/CVE-2019-10963.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10963","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10963"},"summary":{"title":"CVE-2019-10963","description":"Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2019-10-08 19:15:00","updated_at":"2021-10-28 13:24:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html","name":"http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html","refsource":"MISC","tags":[],"title":"Moxa EDR-810 Command Injection / Information Disclosure ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-274-03","name":"https://www.us-cert.gov/ics/advisories/icsa-19-274-03","refsource":"MISC","tags":["Third Party Advisory","US Government Resource"],"title":"Moxa EDR 810 Series | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10963","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10963","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10963","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"moxa","cpe5":"edr-810","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10963","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"moxa","cpe5":"edr-810","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10963","vulnerable":"1","versionEndIncluding":"5.1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"moxa","cpe5":"edr-810_firmware","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10963","qid":"591309","title":"Moxa EDR-810 Series Secure Routers Improper Input Validation Multiple Vulnerabilities (ICSA-19-274-03, MPSA-190906)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10963","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Moxa EDR 810","version":{"version_data":[{"version_value":"All versions 5.1 and prior"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"USE OF HARD-CODED CRYPTOGRAPHIC KEY CWE-321"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-19-274-03","url":"https://www.us-cert.gov/ics/advisories/icsa-19-274-03"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html","url":"http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html"}]},"description":{"description_data":[{"lang":"eng","value":"Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user."}]}},"nvd":{"publishedDate":"2019-10-08 19:15:00","lastModifiedDate":"2021-10-28 13:24:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:moxa:edr-810_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"5.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:moxa:edr-810:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10963","Ordinal":"149244","Title":"CVE-2019-10963","CVE":"CVE-2019-10963","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10963","Ordinal":"1","NoteData":"Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10963","Ordinal":"2","NoteData":"2019-10-08","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10963","Ordinal":"3","NoteData":"2019-10-23","Type":"Other","Title":"Modified"}]}}}