CVE-2019-10963
published 2019-10-08CVE-2019-10963: Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive…
PriorityP335medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EXPLOIT
EPSS
6.34%
92.8th percentile
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | edr-810_firmware | <= 5.1 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa EDR 810 Series
cisa_ics·2019-10-02·CVSS 4.3
[MEDIUM] Moxa EDR 810 Series
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa EDR 810 Series
Last RevisedOctober 02, 2019
Alert CodeICSA-19-274-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.2
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Moxa
- Equipment: EDR 810
- Vulnerabilities: Improper Input Validation, Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow remote code execution or access to sensitive information.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of the Moxa EDR 810 router are affected:
EDR-810: All versions 5.1 and prior
## 3.
GHSA
GHSA-8gff-6cc3-2wfw: Moxa EDR 810, all versions 5
ghsa_unreviewed·2022-05-24
CVE-2019-10963 [MEDIUM] GHSA-8gff-6cc3-2wfw: Moxa EDR 810, all versions 5
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.htmlhttps://www.us-cert.gov/ics/advisories/icsa-19-274-03http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.htmlhttps://www.us-cert.gov/ics/advisories/icsa-19-274-03
2019-10-08
Published