CVE-2019-9101 is a sensitive information disclosure vulnerability affecting several Moxa MGate MB series devices, including the MB3170/MB3270 (before v4.1), MB3280/MB3480 (before v3.1), MB3660 (before v2.3), and MB3180 (before v2.1). The vulnerability, rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), allows an unauthenticated attacker to intercept cleartext credentials transmitted between a web browser and the device's web server by observing network traffic. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0CPE matchmatch criteria | cpe:2.3:o:moxa:mb3170_firmware:*:*:*:*:*:*:*:* | ||
<= 4.0CPE matchmatch criteria | cpe:2.3:o:moxa:mb3270_firmware:*:*:*:*:*:*:*:* | ||
<= 2.0CPE matchmatch criteria | cpe:2.3:o:moxa:mb3180_firmware:*:*:*:*:*:*:*:* | ||
<= 3.0CPE matchmatch criteria | cpe:2.3:o:moxa:mb3280_firmware:*:*:*:*:*:*:*:* | ||
<= 3.0CPE matchmatch criteria | cpe:2.3:o:moxa:mb3480_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.