Vulnerability Details CVE-2019-6563
Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could lead to a full compromise of the device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2019-6563
-
cpe:2.3:h:moxa:eds-405a:-
-
cpe:2.3:h:moxa:eds-408a:-
-
cpe:2.3:h:moxa:eds-510a:-
-
cpe:2.3:h:moxa:iks-g6824a:-
-
cpe:2.3:o:moxa:eds-405a_firmware:3.8
-
cpe:2.3:o:moxa:eds-408a_firmware:3.8
-
cpe:2.3:o:moxa:eds-510a_firmware:3.8
-
cpe:2.3:o:moxa:iks-g6824a_firmware:4.5