Moxa Mgate Mb3180 Firmware vulnerabilities

4 known vulnerabilities affecting moxa/mgate_mb3180_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2021-4161HIGHCVSS 7.5≤ 2.22021-12-27
CVE-2021-4161 [CRITICAL] CWE-319 CVE-2021-4161: The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffi The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
nvd
CVE-2021-33824HIGHCVSS 7.5v2.12021-06-18
CVE-2021-33824 [HIGH] CWE-400 CVE-2021-33824: An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttpt An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.
nvd
CVE-2021-33823HIGHCVSS 7.5v2.12021-06-18
CVE-2021-33823 [HIGH] CVE-2021-33823: An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.
nvd
CVE-2016-5804CRITICALCVSS 9.8fixed in 1.82016-07-15
CVE-2016-5804 [CRITICAL] CWE-326 CVE-2016-5804: Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
nvd