← Voltar para CVEs
CVE-2016-5804
CRITICAL9.8
Descricao
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/15/2016
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
moxa:mgate_mb3170moxa:mgate_mb3170_firmwaremoxa:mgate_mb3180moxa:mgate_mb3180_firmwaremoxa:mgate_mb3270moxa:mgate_mb3270_firmwaremoxa:mgate_mb3280moxa:mgate_mb3280_firmwaremoxa:mgate_mb3480moxa:mgate_mb3480_firmware
Fraquezas (CWE)
CWE-326
Referencias
http://www.securityfocus.com/bid/91777(ics-cert@hq.dhs.gov)
https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02(ics-cert@hq.dhs.gov)
http://www.securityfocus.com/bid/91777(af854a3a-2127-422b-91ae-364da2661108)
https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.