CVE-2019-9101
Description
Cleartext transmission of sensitive information in Moxa MGate MB3xxx series gateways allows an attacker to capture credentials by observing network traffic.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cleartext transmission of sensitive information in Moxa MGate MB3xxx series gateways allows an attacker to capture credentials by observing network traffic.
Vulnerability
An issue was discovered in Moxa MGate MB3170, MB3180, MB3270, MB3280, MB3480, and MB3660 series protocol gateways prior to firmware versions 4.1, 2.1, 4.1, 3.1, 3.1, and 2.3 respectively [1]. The web server transmits sensitive information, including credentials, in cleartext over the network [1][2]. This vulnerability corresponds to Cleartext Transmission of Sensitive Information (CWE-319) [1].
Exploitation
An attacker with the ability to observe network traffic between a web browser and the affected gateway can capture cleartext credentials without any authentication or special privileges [1][2]. The attack can be performed remotely and requires low skill [1]. No user interaction beyond normal administrative use of the web interface is needed.
Impact
Successful exploitation allows the attacker to obtain login credentials (usernames and passwords) transmitted in cleartext [1][2]. This can lead to unauthorized access to the gateway, potentially enabling further attacks such as device configuration changes or network access.
Mitigation
Moxa has released updated firmware to address this vulnerability: MB3170/MB3270 firmware version 4.1, MB3180 firmware version 2.1, MB3280/MB3480 firmware version 3.1, and MB3660 firmware version 2.3 [1][2]. Users should update to these fixed versions as soon as possible. If immediate patching is not possible, it is recommended to restrict network access to the web interface and use encrypted channels (e.g., VPN) to protect traffic.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Moxa/MGate MB3170description
- Range: <3.1
- Range: <4.1
- Range: <4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- www.moxa.com/en/support/support/security-advisory/mb3710-3180-3270-3280-3480-3660-vulnerabilitiesmitrex_refsource_CONFIRM
- www.us-cert.gov/ics/advisories/icsa-20-056-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.