CVE-2016-5804
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
Published:Jul 15, 2016
Last Modified:Apr 12, 2025
EPS:Jul 15, 2016
EPSS Score:0.00179
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Moxa
Product
Mgate Mb3170
Moxa
Mgate Mb3170
Vendor
Moxa
Product
Mgate Mb3170 Firmware
Moxa
Mgate Mb3170 Firmware
Vendor
Moxa
Product
Mgate Mb3180
Moxa
Mgate Mb3180
Vendor
Moxa
Product
Mgate Mb3180 Firmware
Moxa
Mgate Mb3180 Firmware
Vendor
Moxa
Product
Mgate Mb3270
Moxa
Mgate Mb3270
Vendor
Moxa
Product
Mgate Mb3270 Firmware
Moxa
Mgate Mb3270 Firmware
Vendor
Moxa
Product
Mgate Mb3280
Moxa
Mgate Mb3280
Vendor
Moxa
Product
Mgate Mb3280 Firmware
Moxa
Mgate Mb3280 Firmware
Vendor
Moxa
Product
Mgate Mb3480
Moxa
Mgate Mb3480
Vendor
Moxa
Product
Mgate Mb3480 Firmware
Moxa
Mgate Mb3480 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
