CVE-2016-5804

Severity CVSS v4.0:
Pending analysis
Type:
CWE-326 Inadequate Encryption Strength
Publication date:
15/07/2016
Last modified:
12/04/2025

Description

Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:mgate_mb3180_firmware:*:*:*:*:*:*:*:* 1.8 (excluding)
cpe:2.3:h:moxa:mgate_mb3180:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:mgate_mb3280_firmware:*:*:*:*:*:*:*:* 2.7 (excluding)
cpe:2.3:h:moxa:mgate_mb3280:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:mgate_mb3480_firmware:*:*:*:*:*:*:*:* 2.6 (excluding)
cpe:2.3:h:moxa:mgate_mb3480:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:mgate_mb3170_firmware:*:*:*:*:*:*:*:* 2.5 (excluding)
cpe:2.3:h:moxa:mgate_mb3170:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:mgate_mb3270_firmware:*:*:*:*:*:*:*:* 2.7 (excluding)
cpe:2.3:h:moxa:mgate_mb3270:-:*:*:*:*:*:*:*