Description
The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
Published: 2021-12-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Moxa has developed the following mitigations to address this vulnerability. Enable ‘HTTPS’ and disable the HTTP console function under ‘Console Settings’ Moxa also recommends users refer to Tech Note: Moxa Security Hardening Guide for MGate MB3000 Series

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-34029 The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.
History

No history.

Subscriptions

Moxa Mgate Mb3180 Mgate Mb3180 Firmware Mgate Mb3280 Mgate Mb3280 Firmware Mgate Mb3480 Mgate Mb3480 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-16T19:24:13.483Z

Reserved: 2021-12-23T00:00:00.000Z

Link: CVE-2021-4161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-27T19:15:08.803

Modified: 2024-11-21T06:37:02.533

Link: CVE-2021-4161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses