Multiple vulnerabilities were identified in Moxa’s MGate 5105-MB-EIP Series Protocol Gateways. In response to this, Moxa has developed a solution to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Authentication Bypass by Capture-replay (CWE-294) CVE-2020-15494, ZDI-CAN-10791 |
This vulnerability allows an attacker to obtain the session ID of the connection between the host and the device. |
| 2 | Exposure of Sensitive Information to an Unauthorized Actor (CEW-200) CVE-2020-15493, ZDI-CAN-10792 |
This vulnerability allows an attacker to decrypt the encrypted configuration file of the device. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mgate-5105-mb-eip-series-protocol-gateways-vulnerabilities