← back
CVE-2019-5142

CVE-2019-5142

CVSS 7.2 HIGHEPSS 6.9%CWE-78
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 6.9%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various authenticated requests to trigger this vulnerability.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · Moxa

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →