CVE-2019-6526
15.04.2019, 12:31
Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior use plaintext transmission of sensitive data, which may allow an attacker to capture sensitive data such as an administrative password.Enginsight
Vendor | Product | Version |
---|---|---|
moxa | iks-g6824a_firmware | 𝑥 ≤ 4.5 |
moxa | eds-405a_firmware | 𝑥 ≤ 3.8 |
moxa | eds-408a_firmware | 𝑥 ≤ 3.8 |
moxa | eds-510a_firmware | 𝑥 ≤ 3.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.