Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2016-5804 Details
Description
Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB3270 before 2.7 use weak encryption, which allows remote attackers to bypass authentication via a brute-force series of guesses for a parameter value.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02 | CVE | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/91777 | CVE | Third Party AdvisoryVDB Entry |
| https://ics-cert.us-cert.gov/advisories/ICSA-16-196-02 | [email protected] | Third Party AdvisoryUS Government Resource |
| http://www.securityfocus.com/bid/91777 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-326 | Inadequate Encryption Strength | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| moxa mgate mb3180 firmware | < 1.8 |
CPE
Remediation
| |
| moxa mgate mb3180 | All versions |
CPE
Remediation
| |
| moxa mgate mb3280 firmware | < 2.7 |
CPE
Remediation
| |
| moxa mgate mb3280 | All versions |
CPE
Remediation
| |
| moxa mgate mb3480 firmware | < 2.6 |
CPE
Remediation
| |
| moxa mgate mb3480 | All versions |
CPE
Remediation
| |
| moxa mgate mb3170 firmware | < 2.5 |
CPE
Remediation
| |
| moxa mgate mb3170 | All versions |
CPE
Remediation
| |
| moxa mgate mb3270 firmware | < 2.7 |
CPE
Remediation
| |
| moxa mgate mb3270 | All versions |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jul 16, 2021 | Modified Analysis | [email protected] |
| Jul 16, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 16, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 16, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 16, 2021 | CPE Deprecation Remap | [email protected] |
| Jul 16, 2021 | CPE Deprecation Remap | [email protected] |
| Nov 28, 2016 | CVE Modified | [email protected] |
| Jul 19, 2016 | Modified Analysis | [email protected] |
| Jul 19, 2016 | Initial Analysis | [email protected] |