{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-23T00:16:20.582","vulnerabilities":[{"cve":{"id":"CVE-2019-6520","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2019-03-05T20:29:00.297","lastModified":"2026-06-17T02:39:11.007","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration changes."},{"lang":"es","value":"Moxa IKS y EDS no comprueban adecuadamente la autoridad del lado del servidor, lo que resulta en que un usuario de solo lectura sea capaz de realizar cambios arbitrarios en la configuración."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"ICS-CERT","product":"Moxa IKS, EDS","versions":[{"version":"IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:moxa:iks-g6824a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"4.5","matchCriteriaId":"0315E6E6-AD90-4B57-8A2C-23A435CDD9A1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:moxa:iks-g6824a:-:*:*:*:*:*:*:*","matchCriteriaId":"4A845716-E0AF-4DF3-AFAD-2D19456ACAEE"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:moxa:eds-405a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"3.8","matchCriteriaId":"24BC0C6E-9FD5-4956-8A9A-CFEB597638D7"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:moxa:eds-405a:-:*:*:*:*:*:*:*","matchCriteriaId":"66C5DF82-A91D-4966-A841-5B5235316ED4"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:moxa:eds-408a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"3.8","matchCriteriaId":"79E6E8C1-ABB6-4FA1-87BC-338131D9C8FA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:moxa:eds-408a:-:*:*:*:*:*:*:*","matchCriteriaId":"316407E3-51E2-4622-99CE-B683B91741D3"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:moxa:eds-510a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"3.8","matchCriteriaId":"4C2BF052-733D-4B18-8D4F-A8E9E27D5980"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:moxa:eds-510a:-:*:*:*:*:*:*:*","matchCriteriaId":"819581F2-3AF9-4F2A-A9D2-1BDE853C73B9"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/107178","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.securityfocus.com/bid/107178","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}