Remote Code Execution Vulnerabilities in Moxa IKS and EDS Products
CVE-2019-6557
9.8CRITICAL
What is CVE-2019-6557?
Multiple buffer overflow vulnerabilities have been discovered in Moxa's IKS and EDS series of networking products. These vulnerabilities could be exploited by attackers to execute arbitrary code remotely, potentially compromising the integrity and security of the devices. It is crucial for users and organizations utilizing these products to apply necessary updates and follow best security practices to mitigate these risks.
Affected Version(s)
Moxa IKS, EDS IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
