Vulnerability Details CVE-2019-6520
Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-6520
-
cpe:2.3:h:moxa:eds-405a:-
-
cpe:2.3:h:moxa:eds-408a:-
-
cpe:2.3:h:moxa:eds-510a:-
-
cpe:2.3:h:moxa:iks-g6824a:-
-
cpe:2.3:o:moxa:eds-405a_firmware:3.8
-
cpe:2.3:o:moxa:eds-408a_firmware:3.8
-
cpe:2.3:o:moxa:eds-510a_firmware:3.8
-
cpe:2.3:o:moxa:iks-g6824a_firmware:4.5