Moxa Mb3170 Firmware vulnerabilities
9 known vulnerabilities affecting moxa/mb3170_firmware.
Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH4MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-9096CRITICALCVSS 9.8≤ 4.02020-03-11
CVE-2019-9096 [CRITICAL] CWE-521 CVE-2019-9096: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords.
nvd
CVE-2019-9099CRITICALCVSS 9.8≤ 4.02020-03-11
CVE-2019-9099 [CRITICAL] CWE-120 CVE-2019-9099: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).
nvd
CVE-2019-9095CRITICALCVSS 9.8≤ 4.02020-03-11
CVE-2019-9095 [CRITICAL] CWE-327 CVE-2019-9095: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administrative access.
nvd
CVE-2019-9101HIGHCVSS 7.5≤ 4.02020-03-11
CVE-2019-9101 [HIGH] CWE-319 CVE-2019-9101: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe traffic between the web browser and t
nvd
CVE-2019-9102HIGHCVSS 8.8≤ 4.02020-03-11
CVE-2019-9102 [HIGH] CWE-330 CVE-2019-9102: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.
nvd
CVE-2019-9098HIGHCVSS 7.5≤ 4.02020-03-11
CVE-2019-9098 [HIGH] CWE-190 CVE-2019-9098: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS.
nvd
CVE-2019-9104HIGHCVSS 7.5≤ 4.02020-03-11
CVE-2019-9104 [HIGH] CWE-312 CVE-2019-9104: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.
nvd
CVE-2019-9103MEDIUMCVSS 5.3≤ 4.02020-03-11
CVE-2019-9103 [MEDIUM] CWE-200 CVE-2019-9103: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in WEB-service without authorization.
nvd
CVE-2019-9097MEDIUMCVSS 5.3≤ 4.02020-03-11
CVE-2019-9097 [MEDIUM] CVE-2019-9097: An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 device
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A high rate of transit traffic may cause a low-memory condition and a denial of service.
nvd