HIGH🇵🇱 Wersja polska

CVE-2018-10695

CVSS 8.8v3.0pub. 2019-06-07upd. 2024-11-21

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides alert functionality so that an administrator can send emails to his/her account when there are changes to the device's network. However, the same functionality allows an attacker to execute commands on the device. The POST parameters "to1,to2,to3,to4" are all susceptible to buffer overflow. By crafting a packet that contains a string of 678 characters, it is possible for an attacker to execute the attack.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Moxa Awk 3121

    HW
    Moxa
    all versions
  • Moxa Awk 3121 Firmware

    OS
    Moxa
    1.14
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2018-10698CRITICAL9.8PL ✓same product

Moxa AWK-3121: Niezaszyfrowana usługa TELNET z domyślnymi danymi logowania

CVE-2018-10690HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device by default allows HTTP traffic thus providin...

CVE-2018-10693HIGH8.8same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It provides ping functionality so that an administrator...

CVE-2018-10694HIGH8.1same product

An issue was discovered on Moxa AWK-3121 1.14 devices. The device provides a Wi-Fi connection that is open and...

CVE-2018-10691HIGH7.5same product

An issue was discovered on Moxa AWK-3121 1.14 devices. It is intended that an administrator can download /syst...