Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.80% | — | Moxa Mgate Mb3170i FirmwareMoxa Mgate Mb3170i-t FirmwareMoxa Mgate Mb3170-m-st FirmwareMoxa Mgate Mb3170-m-sc-t Firmware+16 | 15/4/2022 | 17/6/2026 | A vulnerability has been discovered in Moxa MGate which allows an attacker to perform a man-in-the-middle (MITM) attack on the device. This affects MGate MB3170 Series Firmware Version 4.2 or lower. and MGate MB3270 Series Firmware Version 4.2 or lower. and MGate MB3280 Series Firmware Version 4.1 or lower. and MGate… | |
| Modificada | Alta (7.5) | 0.66% | — | Moxa Mgate Mb3180 FirmwareMoxa Mgate Mb3280 FirmwareMoxa Mgate Mb3480 Firmware | 27/12/2021 | 17/6/2026 | The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server. | |
| Modificada | Alta (7.5) | 1.0% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext. | |
| Modificada | Media (5.3) | 1.3% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker can access sensitive information (e.g., conduct username disclosure attacks) on the built-in WEB-service without authorization. | |
| Modificada | Alta (8.8) | 1.6% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism. | |
| Modificada | Alta (7.5) | 0.97% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Sensitive information is sent to the web server in cleartext, which may allow an attacker to discover the credentials if they are able to observe… | |
| Modificada | Crítica (9.8) | 4.0% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2). | |
| Modificada | Alta (7.5) | 2.2% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An Integer overflow in the built-in web server allows remote attackers to initiate DoS. | |
| Modificada | Media (5.3) | 1.5% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A high rate of transit traffic may cause a low-memory condition and a denial of service. | |
| Modificada | Crítica (9.8) | 1.8% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. Insufficient password requirements for the MGate web application may allow an attacker to gain access by brute-forcing account passwords. | |
| Modificada | Crítica (9.8) | 0.72% | — | Moxa Mb3170 FirmwareMoxa Mb3270 FirmwareMoxa Mb3180 FirmwareMoxa Mb3280 Firmware+2 | 11/3/2020 | 17/6/2026 | An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. An attacker may be able to intercept weakly encrypted passwords and gain administrative access. | |
| Modificada | Crítica (9.8) | 1.1% | — | Moxa Mgate Mb3180 FirmwareMoxa Mgate Mb3280 FirmwareMoxa Mgate Mb3480 FirmwareMoxa Mgate Mb3170 Firmware+1 | 15/7/2016 | 17/6/2026 | Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value. |