{"api_version":"1","generated_at":"2026-06-05T10:25:06+00:00","cve":"CVE-2021-33824","urls":{"html":"https://cve.report/CVE-2021-33824","api":"https://cve.report/api/cve/CVE-2021-33824.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-33824","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-33824"},"summary":{"title":"CVE-2021-33824","description":"An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-06-18 20:15:00","updated_at":"2021-06-24 19:01:00"},"problem_types":["CWE-400"],"metrics":[],"references":[{"url":"https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.md","name":"https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.md","refsource":"MISC","tags":[],"title":"CVE-POC/CVE-2021-33824.md at master · Jian-Xian/CVE-POC · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/shekyan/slowhttptest","name":"https://github.com/shekyan/slowhttptest","refsource":"MISC","tags":[],"title":"GitHub - shekyan/slowhttptest: Application Layer DoS attack simulator","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.moxa.com/en/products/industrial-edge-connectivity/protocol-gateways/modbus-tcp-gateways/mgate-mb3180-mb3280-mb3480-series","name":"https://www.moxa.com/en/products/industrial-edge-connectivity/protocol-gateways/modbus-tcp-gateways/mgate-mb3180-mb3280-mb3480-series","refsource":"MISC","tags":[],"title":"MGate MB3180/MB3280/MB3480 Series - Modbus TCP Gateways  | MOXA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-33824","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33824","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"33824","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"moxa","cpe5":"mgate_mb3180","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"33824","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"moxa","cpe5":"mgate_mb3180_firmware","cpe6":"2.1","cpe7":"build_18113012","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-33824","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/shekyan/slowhttptest","refsource":"MISC","name":"https://github.com/shekyan/slowhttptest"},{"url":"https://www.moxa.com/en/products/industrial-edge-connectivity/protocol-gateways/modbus-tcp-gateways/mgate-mb3180-mb3280-mb3480-series","refsource":"MISC","name":"https://www.moxa.com/en/products/industrial-edge-connectivity/protocol-gateways/modbus-tcp-gateways/mgate-mb3180-mb3280-mb3480-series"},{"refsource":"MISC","name":"https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.md","url":"https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.md"}]}},"nvd":{"publishedDate":"2021-06-18 20:15:00","lastModifiedDate":"2021-06-24 19:01:00","problem_types":["CWE-400"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:moxa:mgate_mb3180_firmware:2.1:build_18113012:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:moxa:mgate_mb3180:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"33824","Ordinal":"209264","Title":"CVE-2021-33824","CVE":"CVE-2021-33824","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"33824","Ordinal":"1","NoteData":"An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"33824","Ordinal":"2","NoteData":"2021-06-18","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"33824","Ordinal":"3","NoteData":"2021-06-18","Type":"Other","Title":"Modified"}]}}}