Vulnerability Details CVE-2019-9102
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. A predictable mechanism of generating tokens allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.2%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 6.8
Products affected by CVE-2019-9102
-
-
-
-
-
-
-
cpe:2.3:o:moxa:mb3170_firmware:4.0
-
cpe:2.3:o:moxa:mb3180_firmware:2.0
-
cpe:2.3:o:moxa:mb3270_firmware:4.0
-
cpe:2.3:o:moxa:mb3280_firmware:3.0
-
cpe:2.3:o:moxa:mb3480_firmware:3.0
-
cpe:2.3:o:moxa:mb3660_firmware:2.2