Product support

Security Advisories

SUMMARY

MGate 5105-MB-EIP Series Protocol Gateways Vulnerability

  • Version: V1.0
  • Release Date: Jan 06, 2020
  • Reference:
    • N/A

A product vulnerability was identified in Moxa’s MGate 5105-MB-EIP Series Protocol Gateways. In response to this, Moxa has developed related solutions to address this vulnerability..

The identified vulnerability type and potential impacts are shown below:

Item Vulnerability Type Impact
1 Command Injection A Command Injection vulnerability exists in the web server of the MGate 5105-MB-EIP Series that could allow a remote attacker to execute arbitrary commands.
AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
MGate 5105-MB-EIP Series Firmware Version 4.1 or lower

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below.

Product Series Solutions
MGate 5105-MB-EIP Series Please download the new firmware/software here.

 

Acknowledgment:

We would like to express our appreciation to Dove Chiu, Philippe Lin, Charles Perine, Marco Balduzzi, Ryan Flores, and Rainer Vosseler working with Trend Micro's Zero Day Initiative for reporting the vulnerability, working with us to help enhance the security of our products, and helping us provide a better service to our customers.

 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Jan 06, 2020

Relevant Products

MGate 5105-MB-EIP Series ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag