First published: Wed Mar 11 2020(Updated: )
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Mgate MB3170 Firmware | <=4.0 | |
Moxa MGate MB3170 | ||
Moxa Mgate Mb3270 Firmware | <=4.0 | |
Moxa Mgate MB3270 | ||
Moxa Mgate MB3180 Firmware | <=2.0 | |
Moxa MGate MB3180 Series | ||
Moxa Mgate Mb3280 Firmware | <=3.0 | |
Moxa Mgate Mb3280 | ||
Moxa Mgate Mb3480 Firmware | <=3.0 | |
Moxa MGate MB3480 Series | ||
Moxa Mb3660 Firmware | <=2.2 | |
Moxa Mb3660 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9099 has a high severity rating due to its potential for remote code execution and denial of service.
To fix CVE-2019-9099, update the firmware of the affected Moxa devices to the latest version.
CVE-2019-9099 affects Moxa MGate MB3170, MB3270, MB3280, MB3480, and MB3660 devices with specific firmware versions.
Yes, CVE-2019-9099 allows remote attackers to initiate denial of service attacks on affected devices.
Yes, CVE-2019-9099 may allow attackers to execute arbitrary code on the vulnerable Moxa devices.