CVE-2019-9102

EUVD-2019-18487
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AC:L/AV:N/A:L/C:N/I:L/PR:N/S:U/UI:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
moxamb3170_firmware
𝑥
≤ 4.0
moxamb3270_firmware
𝑥
≤ 4.0
moxamb3180_firmware
𝑥
≤ 2.0
moxamb3280_firmware
𝑥
≤ 3.0
moxamb3480_firmware
𝑥
≤ 3.0
moxamb3660_firmware
𝑥
≤ 2.2
𝑥
= Vulnerable software versions