QID 591162
Date Published: 2022-11-04
QID 591162: Moxa AWK-3131A Multiple iw_* utilities Use of Hard-coded Credentials Vulnerability (TALOS-2019-0928)
AFFECTED PRODUCTS
Moxa AWK-3131A Firmware version 1.13
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.
Solution
Customers are advised to refer to CERT MITIGATIONS section TALOS-2019-0928 for affected packages and patching details.
Vendor References
- TALOS-2019-0928 -
talosintelligence.com/vulnerability_reports/TALOS-2019-0928
CVEs related to QID 591162
Software Advisories
| Advisory ID | Software | Component | Link |
|---|