CVE-2019-10969
high · 7.2Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthorized commands on the router, which may allow an attacker to perform remote code execution.
7.2
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2019-10-08
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| moxa | edr-810_firmware | <= 5.1 |
| moxa | edr-810 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html
- https://www.us-cert.gov/ics/advisories/icsa-19-274-03
- http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.html
- https://www.us-cert.gov/ics/advisories/icsa-19-274-03
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-10969