HIGH🇵🇱 Wersja polska

CVE-2018-10693

CVSS 8.8v3.0pub. 2019-06-07upd. 2024-11-21

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator can execute ICMP calls to check if the network is working correctly. However, the same functionality allows an attacker to execute commands on the device. The POST parameter "srvName" is susceptible to a buffer overflow. By crafting a packet that contains a string of 516 characters, it is possible for an attacker to execute the attack.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Moxa Awk 3121

    HW
    Moxa
    all versions
  • Moxa Awk 3121 Firmware

    OS
    Moxa
    1.14
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2018-10698CRITICAL9.8PL ✓same product

Moxa AWK-3121: Niezaszyfrowana usługa TELNET z domyślnymi danymi logowania

CVE-2018-10690HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providin...

CVE-2018-10694HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and...

CVE-2018-10695HIGH8.8same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrato...

CVE-2018-10691HIGH7.5same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /syst...