Back

CRITICAL

ICSA-21-357-01 Moxa MGate Protocol Gateways

Published Dec 27, 2021

Description

The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

Affected products

Remediation

Vendor solution

Moxa has developed the following mitigations to address this vulnerability.

Enable ‘HTTPS’ and disable the HTTP console function under ‘Console Settings’ Moxa also recommends users refer to Tech Note: Moxa Security Hardening Guide for MGate MB3000 Series

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner icscert
Published Dec 27, 2021
Updated Sep 16, 2024
Reserved Dec 23, 2021

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner icscert
Published Dec 27, 2021
Updated Sep 16, 2024

GitHub

No data