CVE-2019-6561

EUVD-2019-16120
Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
Affected Products (NVD)
VendorProductVersion
moxaiks-g6824a_firmware
𝑥
≤ 4.5
moxaeds-405a_firmware
𝑥
≤ 3.8
moxaeds-408a_firmware
𝑥
≤ 3.8
moxaeds-510a_firmware
𝑥
≤ 3.8
𝑥
= Vulnerable software versions