CVE Vulnerabilities

CVE-2019-6563

Predictable from Observable State

Published: Mar 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrators password, which could lead to a full compromise of the device.

Weakness

A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.

Affected Software

Name Vendor Start Version End Version
Iks-g6824a_firmware Moxa * 4.5 (including)

Potential Mitigations

References