CVE-2019-6522
Status: ModifiedCritical (9.1)—
Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Base score: 9.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.54%
- Percentile among all scored CVEs: 84
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Primary impact
T1005Data from Local Systemcollection - Primary impact
T1499.004Application or System Exploitationimpact
Source: official MITRE CTID mapping (CVE → ATT&CK).
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (4)
CWEs
- CWE-125
- CWE-125
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-6522",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 7.8,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.1,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "ICS-CERT",
"product": "Moxa IKS, EDS",
"versions": [
{
"status": "affected",
"version": "IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and prior, and EDS-510A series Version 3.8 and prior"
}
]
}
]
}
],
"published": "2019-03-05T20:29:00.343",
"references": [
{
"url": "http://www.securityfocus.com/bid/107178",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.securityfocus.com/bid/107178",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-19-057-01",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary addresses, and may allow an attacker to retrieve sensitive data or cause device reboot."
},
{
"lang": "es",
"value": "Moxa IKS y EDS no comprueban adecuadamente los límites de array que podrían permitir que un atacante lea memoria del dispositivo en direcciones arbitrarias y podría permitir que un atacante recupere datos sensibles o provoque el reinicio del dispositivo."
}
],
"lastModified": "2026-06-17T02:39:11.217",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:moxa:iks-g6824a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0315E6E6-AD90-4B57-8A2C-23A435CDD9A1",
"versionEndIncluding": "4.5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:moxa:iks-g6824a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4A845716-E0AF-4DF3-AFAD-2D19456ACAEE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:moxa:eds-405a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24BC0C6E-9FD5-4956-8A9A-CFEB597638D7",
"versionEndIncluding": "3.8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:moxa:eds-405a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "66C5DF82-A91D-4966-A841-5B5235316ED4"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:moxa:eds-408a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79E6E8C1-ABB6-4FA1-87BC-338131D9C8FA",
"versionEndIncluding": "3.8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:moxa:eds-408a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "316407E3-51E2-4622-99CE-B683B91741D3"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:moxa:eds-510a_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4C2BF052-733D-4B18-8D4F-A8E9E27D5980",
"versionEndIncluding": "3.8"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:moxa:eds-510a:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "819581F2-3AF9-4F2A-A9D2-1BDE853C73B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}