CVE-2015-6458
published 2019-03-21CVE-2015-6458: Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on…
PriorityP349high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
2.80%
84.9th percentile
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | softcms | <= 1.3 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8mgx-vxh4-599c: Moxa SoftCMS 1
ghsa_unreviewed·2022-05-13
CVE-2015-6458 [HIGH] CWE-119 GHSA-8mgx-vxh4-599c: Moxa SoftCMS 1
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
CISA ICS
Moxa SoftCMS Buffer Overflow Vulnerabilities
cisa_ics·2018-08-27
Moxa SoftCMS Buffer Overflow Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa SoftCMS Buffer Overflow Vulnerabilities
Last RevisedAugust 27, 2018
Alert CodeICSA-15-239-01
## OVERVIEW
NCCIC/ICS-CERT received a report from HP’s Zero Day Initiative (ZDI) concerning buffer overflow vulnerabilities in Moxa’s SoftCMS software package. These vulnerabilities were reported to ZDI by security researcher Carsten Eiram of Risk Based Security, who identified seven vulnerabilities, and Fritz Sands, who discovered two vulnerabilities. Moxa has released a new version to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-21
Published