CVE-2016-5804
Summary
| CVE | CVE-2016-5804 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-07-15 16:59:00 UTC |
| Updated | 2021-07-16 15:08:00 UTC |
| Description | Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value. |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Moxa | Mgate Mb3170 | - | All | All | All |
| Operating System | Moxa | Mgate Mb3170 Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3170 Router | All | All | All | All |
| Hardware | Moxa | Mgate Mb3170 Router | All | All | All | All |
| Application | Moxa | Mgate Mb3170 Router Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3180 | - | All | All | All |
| Operating System | Moxa | Mgate Mb3180 Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3180 Router | All | All | All | All |
| Hardware | Moxa | Mgate Mb3180 Router | All | All | All | All |
| Application | Moxa | Mgate Mb3180 Router Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3270 | - | All | All | All |
| Operating System | Moxa | Mgate Mb3270 Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3270 Router | All | All | All | All |
| Hardware | Moxa | Mgate Mb3270 Router | All | All | All | All |
| Application | Moxa | Mgate Mb3270 Router Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3280 | - | All | All | All |
| Operating System | Moxa | Mgate Mb3280 Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3280 Router | All | All | All | All |
| Hardware | Moxa | Mgate Mb3280 Router | All | All | All | All |
| Application | Moxa | Mgate Mb3280 Router Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3480 | - | All | All | All |
| Operating System | Moxa | Mgate Mb3480 Firmware | All | All | All | All |
| Hardware | Moxa | Mgate Mb3480 Router | All | All | All | All |
| Hardware | Moxa | Mgate Mb3480 Router | All | All | All | All |
| Application | Moxa | Mgate Mb3480 Router Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | |
| Moxa MGate Authentication Bypass Vulnerability | ICS-CERT | MISC | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.