ZeroHour

CVE-2019-5165

PoC
CVSS 3.1
7.2 high
EPSS
2%p81
Published
()
Modified
Description

An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

Vendors
moxa
Products
awk-3131a firmware
Weakness
CWE-288, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news