First published: Wed Mar 11 2020(Updated: )
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Mb3170 Firmware | <=4.0 | |
Moxa Mb3170 | ||
Moxa Mb3270 Firmware | <=4.0 | |
Moxa Mb3270 | ||
Moxa Mb3180 Firmware | <=2.0 | |
Moxa Mb3180 | ||
Moxa Mb3280 Firmware | <=3.0 | |
Moxa Mb3280 | ||
Moxa Mb3480 Firmware | <=3.0 | |
Moxa Mb3480 | ||
Moxa Mb3660 Firmware | <=2.2 | |
Moxa Mb3660 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-9102.
CVE-2019-9102 has a severity rating of 8.8 (High).
CVE-2019-9102 affects Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1.
CVE-2019-9102 allows remote attackers to bypass Cross-Site Request Forgery (CSRF) protection.
Yes, you can find references for CVE-2019-9102 at the following links: [1] https://www.moxa.com/en/support/support/security-advisory/mb3710-3180-3270-3280-3480-3660-vulnerabilities [2] https://www.us-cert.gov/ics/advisories/icsa-20-056-01