Improper Authentication in Moxa products - #VU25735
Published: March 3, 2020
Vulnerability identifier: #VU25735
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in authentication process. A remote attacker can bypass authentication by logging in with empty username/password and execute arbitrary actions with administrator privileges on an affected system.
Affected software
Moxa MGate MB3180 Series
Moxa MGate MB3270 Series
Moxa MGate MB3170 Series
Moxa MGate MB3480 Series
Moxa MGate MB3280 Series
Moxa MGate MB3270 Series
Moxa MGate MB3170 Series
Moxa MGate MB3480 Series
Moxa MGate MB3280 Series
Remediation
Install updates from vendor's website.
Moxa MGate MB3180 Series - update to 2.1
Moxa MGate MB3270 Series - update to 4.1
Moxa MGate MB3170 Series - update to 4.1
Moxa MGate MB3480 Series - update to 3.1
Moxa MGate MB3280 Series - update to 4.0
Moxa MGate MB3270 Series - update to 4.1
Moxa MGate MB3170 Series - update to 4.1
Moxa MGate MB3480 Series - update to 3.1
Moxa MGate MB3280 Series - update to 4.0