CVE-2019-6522

CWE-125Out-of-bounds Read3 documents3 sources
Severity
9.1CRITICAL
EPSS
0.3%
top 46.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 5
Latest updateMay 13

Description

Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

🔴Vulnerability Details

2
GHSA
GHSA-j83f-2hmq-pjmf: Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attac2022-05-13
CVEList
CVE-2019-6522: Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attac2019-03-05
CVE-2019-6522 (CRITICAL CVSS 9.1) | Moxa IKS and EDS fails to properly | cvebase.io