CVE-2019-5148
published 2020-02-25CVE-2019-5148: An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.58%
83.5th percentile
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | awk-3131a_firmware | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa AWK-3131A Series Industrial AP/Bridge/Client
cisa_ics·2020-03-03·CVSS 8.8
[HIGH] Moxa AWK-3131A Series Industrial AP/Bridge/Client
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa AWK-3131A Series Industrial AP/Bridge/Client
Last RevisedMarch 03, 2020
Alert CodeICSA-20-063-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low skill level is needed to exploit/public exploits are available
- Vendor: Moxa
- Equipment: Moxa AWK-3131A
- Vulnerabilities: Improper Access Control, Use of Hard-coded Cryptographic Key, OS Command Injection, Use of Hard-coded Credentials, Classic Buffer Overflow, Out-of-bounds Read, Stack-based Buffer Overflow, Improper Access Control, Authentication Bypass Using an Alternate Path or Channel
## 2.
GHSA
GHSA-qqr8-vww9-h837: An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1
ghsa_unreviewed·2022-05-24
CVE-2019-5148 [MEDIUM] CWE-191 GHSA-qqr8-vww9-h837: An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1
An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker can send this packet while unauthenticated to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Moxa AWK-3131A
blogs_talos·2020-02-24·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple vulnerabilities in Moxa AWK-3131A
Jared Rittle and Carl Hurd of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
The Moxa AWK-3131A networking device contains several different vulnerabilities that an attacker could exploit to carry out malicious activities in an industrial environment. The AWK-3131A is a wireless networking device that is meant to be used in large-scale, industrial cases to provide
communication across the environment in which it's deployed. This device contains several bugs that could lead to numerous malicious activities, including remote code execution and privilege escalation.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Moxa to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsM
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Moxa AWK-3131A
blogs_talos·2020-02-24·CVSS 8.8
[HIGH] Vulnerability Spotlight: Multiple vulnerabilities in Moxa AWK-3131A
## Vulnerability Spotlight: Multiple vulnerabilities in Moxa AWK-3131A
Jared Rittle and Carl Hurd of Cisco Talos discovered these vulnerabilities. Blog by Jon Munshaw.
The Moxa AWK-3131A networking device contains several different vulnerabilities that an attacker could exploit to carry out malicious activities in an industrial environment. The AWK-3131A is a wireless networking device that is meant to be used in large-scale, industrial cases to provide
communication across the environment in which it's deployed. This device contains several bugs that could lead to numerous malicious activities, including remote code execution and privilege escalation.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Moxa to ensure that these issues are resolved and that an
2020-02-25
Published