CVE-2019-6524

Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover passwords via brute force attack.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
moxaiks-g6824a_firmware
𝑥
≤ 4.5
moxaeds-405a_firmware
𝑥
≤ 3.8
moxaeds-408a_firmware
𝑥
≤ 3.8
moxaeds-510a_firmware
𝑥
≤ 3.8
𝑥
= Vulnerable software versions