CVE-2016-5804
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.12% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-326
- Affected
- moxa/mgate mb3180 firmware · moxa/mgate mb3280 firmware · moxa/mgate mb3480 firmware · moxa/mgate mb3170 firmware · moxa/mgate mb3270 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/91777Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/91777Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.