CVE-2021-4161

CRITICAL

Moxa MGate MB3180 <2.2, MB3280 <4.1, MB3480 <3.2 Cleartext Transmission of Sensitive Info

Title source: llm
STIX 2.1

Description

The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-21-357-01

Scores

CVSS v3 9.8
EPSS 0.0013
EPSS Percentile 31.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (3)
moxa/mgate_mb3180_firmware < 2.2
moxa/mgate_mb3280_firmware < 4.1
moxa/mgate_mb3480_firmware < 3.2
Published Dec 27, 2021
Tracked Since Feb 18, 2026