← Vulnerability feed

Vulnerability record · CVE-2019-6518 · published 5 March 2019

CVE-2019-6518: Moxa iks-g6824a firmware missing encryption vulnerability

Moxa · Iks G6824a Firmware

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

7.5 CVSS 3.1 High EPSS 1.2% · top 31.8% CWE-256 · CWE-256CWE-311 · Missing encryption
7.5CVSS 3.1 base score, v2 5.0
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to the device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/107178 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/bid/107178 Third Party AdvisoryVDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01 Third Party AdvisoryUS Government Resource

Track CVE-2019-6518 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-6526Moxa iks-g6824a firmware missing encryption vulnerabilityMoxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Vers…EPSS 1.00%9.8CVE-2019-6524Moxa iks-g6824a firmware improper restriction of authentication attempts vulnerabilityMoxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allow an attacker to discover pas…EPSS 2.7%9.8CVE-2019-6557Moxa iks-g6824a firmware classic buffer overflow vulnerabilitySeveral buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution.EPSS 5.0%9.8CVE-2019-6563Moxa iks-g6824a firmware vulnerabilityMoxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administrator's password, which could…EPSS 1.7%9.1CVE-2019-6522Moxa iks-g6824a firmware out-of-bounds read vulnerabilityMoxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an atta…EPSS 2.5%8.8CVE-2019-6561Moxa iks-g6824a firmware cross-site request forgery vulnerabilityCross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized actions on the device.EPSS 1.2%8.5CVE-2015-6464Moxa eds-405a firmware vulnerabilityThe administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote authenticated users to bypass a read-o…EPSS 2.6%7.5CVE-2019-6520Moxa iks-g6824a firmware improper access control vulnerabilityMoxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perform arbitrary configuration ch…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2019-6518), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.