CVE-2016-5804
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.8 |
| Running on/with | Platform Versions |
|---|---|
Moxa Mgate Mb3180 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7 |
| Running on/with | Platform Versions |
|---|---|
Moxa Mgate Mb3280 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Mgate Mb3480 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5 |
| Running on/with | Platform Versions |
|---|---|
Moxa Mgate Mb3170 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.7 |
| Running on/with | Platform Versions |
|---|---|
Moxa Mgate Mb3270 | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.