CVE-2019-9099
high-risk
Published 2020-03-11
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).
Do I need to act?
~
9.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (6)
Mb3170 Firmware
Mb3270 Firmware
Mb3180 Firmware
Mb3280 Firmware
Mb3480 Firmware
Mb3660 Firmware
Affected Vendors
References (4)
Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-20-056-01
Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-20-056-01
55
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
10/34 · Low
Exposure
13/34 · Low