Multiple web server vulnerabilities affect EDS-405A version 3.5 and earlier, as well as EDS-408A Series version 3.6 and earlier. These vulnerabilities arise from insufficient input validation and improper privilege management. An attacker could exploit these vulnerabilities by sending crafted HTTP input to the web service. Successful exploitation could lead to a denial-of-service attack, remote code execution, and privilege escalation.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Privilege Management (CWE-269) CVE-2015-6464 |
An attacker could send crafted input to escalate privileges. |
| 2 |
Uncontrolled Resource Exhaustion (CWE-400) CVE-2015-6465 |
The embedded GoAhead web server running on the EDS-405A and EDS-408A is vulnerable to a denial-of-service attack. |
| 3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) CVE-2015-6466 |
An input field in the administrative web interface lacks input validation, which could be abused to inject JavaScript code. |
Vulnerability Scoring Details
|
ID
|
CVSS v2.0
|
Vector
|
Unauthenticated Remote Exploit
|
|---|---|---|---|
| CVE-2015-6464 |
8.2 |
AV:N/AC:L/Au:S/C:N/I:C/A:C | No |
| CVE-2015-6465 | 6.8 | AV:N/AC:L/Au:S/C:N/I:N/A:C | No |
| CVE-2015-6466 | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-154603-eds-405a-408a-series-multiple-web-vulnerabilities