ICSA-21-357-01 Moxa MGate Protocol Gateways
Published Dec 27, 2021
9.8
CRITICALCVSS 3.1
EPSS 0.66%
Description
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
Affected products
-
Affected
- ≥ all, < 2.2
-
Affected
- all 4.1
-
Affected
- all 3.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Moxa | MGate MB3180 Series | unknown | Affected
|
| Moxa | MGate MB3280 Series | unknown | Affected
|
| Moxa | MGate MB3480 Series | unknown | Affected
|
Configuration 1
- ≤ 2.2
Running on/with
- n/a
Configuration 2
- ≤ 4.1
Running on/with
- n/a
Configuration 3
- ≤ 3.2
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Moxa has developed the following mitigations to address this vulnerability.
Enable ‘HTTPS’ and disable the HTTP console function under ‘Console Settings’ Moxa also recommends users refer to Tech Note: Moxa Security Hardening Guide for MGate MB3000 Series
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34029 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-357-01 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-34029 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-21-357-01 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data