CVE Vulnerabilities

CVE-2019-6518

Plaintext Storage of a Password

Published: Mar 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
Iks-g6824a_firmwareMoxa*4.5 (including)

Potential Mitigations

References