QID 591154
Date Published: 2022-11-04
QID 591154: Moxa AWK-3131A iw_webs hostname Authentication Bypass Vulnerability (TALOS-2019-0960)
AFFECTED PRODUCTS
Moxa AWK-3131A Firmware version 1.13
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2019-0960 for affected packages and patching details.
Vendor References
- TALOS-2019-0960 -
talosintelligence.com/vulnerability_reports/TALOS-2019-0960
CVEs related to QID 591154
Software Advisories
| Advisory ID | Software | Component | Link |
|---|