CVE-2019-18238

In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
moxaiologik_2512_firmware
𝑥
≤ 3.0
moxaiologik_2512-t_firmware
𝑥
≤ 3.0
moxaiologik_2512-hspa_firmware
𝑥
≤ 3.0
moxaiologik_2512-hspa-t_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-eu_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-eu-t_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-us_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-us-t_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-jp_firmware
𝑥
≤ 3.0
moxaiologik_2512-wl1-jp-t_firmware
𝑥
≤ 3.0
moxaiologik_2542_firmware
𝑥
≤ 3.0
moxaiologik_2542-t_firmware
𝑥
≤ 3.0
moxaiologik_2542-hspa_firmware
𝑥
≤ 3.0
moxaiologik_2542-hspa-t_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-eu_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-eu-t_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-us_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-us-t_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-jp_firmware
𝑥
≤ 3.0
moxaiologik_2542-wl1-jp-t_firmware
𝑥
≤ 3.0
𝑥
= Vulnerable software versions