TROYANOSYVIRUS
Voltar para CVEs

CVE-2016-5804

CRITICAL
9.8

Descricao

Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.

Detalhes CVE

Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado7/15/2016
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

moxa:mgate_mb3170moxa:mgate_mb3170_firmwaremoxa:mgate_mb3180moxa:mgate_mb3180_firmwaremoxa:mgate_mb3270moxa:mgate_mb3270_firmwaremoxa:mgate_mb3280moxa:mgate_mb3280_firmwaremoxa:mgate_mb3480moxa:mgate_mb3480_firmware

Fraquezas (CWE)

CWE-326

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.