CVE-2019-9104
published 2020-03-11CVE-2019-9104: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.06%
60.8th percentile
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | mb3170_firmware | <= 4.0 | — |
| moxa | mb3180_firmware | <= 2.0 | — |
| moxa | mb3270_firmware | <= 4.0 | — |
| moxa | mb3280_firmware | <= 3.0 | — |
| moxa | mb3480_firmware | <= 3.0 | — |
| moxa | mb3660_firmware | <= 2.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MB3xxx Series Protocol Gateways
cisa_ics·2020-02-25·CVSS 9.8
[CRITICAL] Moxa MB3xxx Series Protocol Gateways
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MB3xxx Series Protocol Gateways
Last RevisedFebruary 25, 2020
Alert CodeICSA-20-056-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Moxa
- Equipment: MB3170 series, MB3180 series, MB3270 series, MB3280 series, MB3480 series, and MB3660 series
- Vulnerabilities: Stack-based Buffer Overflow, Integer Overflow to Buffer Overflow, Cross-site Request Forgery, Use of a Broken or Risky Cryptographic Algorithm, Information Exposure, Cleartext Transmission of Sensitive Information, Weak Password Requirements, Clearte
GHSA
GHSA-rx6c-qrhp-f4hq: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4
ghsa_unreviewed·2022-05-24
CVE-2019-9104 [MEDIUM] CWE-522 GHSA-rx6c-qrhp-f4hq: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.moxa.com/en/support/support/security-advisory/mb3710-3180-3270-3280-3480-3660-vulnerabilitieshttps://www.us-cert.gov/ics/advisories/icsa-20-056-01https://www.moxa.com/en/support/support/security-advisory/mb3710-3180-3270-3280-3480-3660-vulnerabilitieshttps://www.us-cert.gov/ics/advisories/icsa-20-056-01
2020-03-11
Published