CVE ID | CVE-2015-6480 |
CVSS SCORE | 7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P |
AFFECTED VENDORS |
Moxa |
AFFECTED PRODUCTS |
OnCell Central Manager |
TREND MICRO CUSTOMER PROTECTION | Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID ['19418']. For further product information on the TippingPoint IPS: http://www.tippingpoint.com |
VULNERABILITY DETAILS |
The specific flaw exists within the MessageBrokerServlet servlet, which does not ensure a user is authenticated prior to accepting commands. An attacker can exploit this condition to perform various actions, including addUserAndGroup, to take full control of the product and achieve code execution on all managed hosts. |
ADDITIONAL DETAILS |
02/05/2015 - ZDI sent reports to ICS-CERT -- Mitigation: -- Vendor Patch:
|
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi (rgod) |