VulnerabilityModified
CVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure.
MEDIUM 4.3EPSS 6.50%
Does this matter?
Lower severity and a low EPSS score (6.50%). Track it; it rarely justifies an emergency change on its own.
Description
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 6.50% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-321
- Affected
- moxa/edr-810 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-274-03Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/154943/Moxa-EDR-810-Command-Injection-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://www.us-cert.gov/ics/advisories/icsa-19-274-03Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.