Improper Authentication in Moxa products - #VU25735

 

Improper Authentication in Moxa products - #VU25735

Published: March 3, 2020


Vulnerability identifier: #VU25735
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in authentication process. A remote attacker can bypass authentication by logging in with empty username/password and execute arbitrary actions with administrator privileges on an affected system.


Affected software

Moxa MGate MB3180 Series
Moxa MGate MB3270 Series
Moxa MGate MB3170 Series
Moxa MGate MB3480 Series
Moxa MGate MB3280 Series

Remediation

Install updates from vendor's website.

Moxa MGate MB3180 Series - update to 2.1
Moxa MGate MB3270 Series - update to 4.1
Moxa MGate MB3170 Series - update to 4.1
Moxa MGate MB3480 Series - update to 3.1
Moxa MGate MB3280 Series - update to 4.0

External References

Related Security Bulletins