CVE-2016-5804
published 2016-07-15CVE-2016-5804: Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.12%
62.3th percentile
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mgate_mb3170_firmware | < 2.5 | 2.5 |
| moxa | mgate_mb3180_firmware | < 1.8 | 1.8 |
| moxa | mgate_mb3270_firmware | < 2.7 | 2.7 |
| moxa | mgate_mb3280_firmware | < 2.7 | 2.7 |
| moxa | mgate_mb3480_firmware | < 2.6 | 2.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MGate Authentication Bypass Vulnerability
cisa_ics·2018-08-23
Moxa MGate Authentication Bypass Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MGate Authentication Bypass Vulnerability
Last RevisedAugust 23, 2018
Alert CodeICSA-16-196-02
## OVERVIEW
Independent researcher Maxim Rupp has identified an authentication bypass vulnerability in Moxa’s MGate products. Moxa has produced new firmware versions to mitigate this vulnerability.
This vulnerability could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerability affects the following products:
- MGate MB3180, versions prior to v1.8,
- MGate MB3280, versions prior to v2.7,
- MGate MB3480, versions prior to v2.6,
- MGate MB3170, version
GHSA
GHSA-5cr2-3qp3-5h49: Moxa MGate MB3180 before 1
ghsa_unreviewed·2022-05-13
CVE-2016-5804 [CRITICAL] CWE-326 GHSA-5cr2-3qp3-5h49: Moxa MGate MB3180 before 1
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-07-15
Published