peter bassill · operator
$ cve CVE-2019-9099 JSON

CVE-2019-9099

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A Buffer overflow in the built-in web server allows remote attackers to initiate DoS, and probably to execute arbitrary code (issue 1 of 2).

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.05% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2020-03-11
Last modified2026-06-17

Affected (12)

VendorProduct
moxamb3170
moxamb3170 firmware
moxamb3180
moxamb3180 firmware
moxamb3270
moxamb3270 firmware
moxamb3280
moxamb3280 firmware
moxamb3480
moxamb3480 firmware
moxamb3660
moxamb3660 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD