CyberSec.Space Logo
CVEブラウザに戻る

CVE-2019-5138

CRITICAL
9.9
CVSS Severity Score
EPSS Score0.0040%
EPSS Percentile32.59th
Published2020年2月25日
Last Modified2024年11月21日

Vulnerability Description

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

Affected Platforms (CPE)

💻
Moxa

Awk 3131a Firmware

= 1.13

References & Advisories

関連する脆弱性情報

CVE-2019-5138 Detail & Impact Analysis | CVSS 9.9 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space