VYPR
Unrated severityNVD Advisory· Published Mar 11, 2020· Updated Aug 4, 2024

CVE-2019-9104

CVE-2019-9104

Description

Cleartext storage of passwords in configuration files on Moxa MGate MB3xxx series gateways allows local attackers to gain unauthorized access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cleartext storage of passwords in configuration files on Moxa MGate MB3xxx series gateways allows local attackers to gain unauthorized access.

Vulnerability

The configuration files on Moxa MGate MB3170, MB3180, MB3270, MB3280, MB3480, and MB3660 series protocol gateways store passwords in cleartext. This affects MB3170 and MB3270 devices running firmware version 4.0 or lower, MB3280 and MB3480 devices running firmware version 3.0 or lower, MB3660 devices running firmware version 2.2 or lower, and MB3180 devices running firmware version 2.0 or lower [1][2].

Exploitation

An attacker with local access to the device or the ability to retrieve the configuration file (e.g., via another vulnerability such as information disclosure) can read the cleartext passwords [1]. No authentication is required to perform this step if the attacker already has access to the file.

Impact

Successful exploitation allows the attacker to obtain sensitive credentials (e.g., for web interface or other services) and subsequently gain unauthorized access to the device with the privileges associated with those passwords [1]. This could lead to full compromise of the device and the network segment it controls.

Mitigation

Moxa released fixed firmware versions: 4.1 for MB3170 and MB3270, 3.1 for MB3280 and MB3480, 2.3 for MB3660, and 2.1 for MB3180 [1][2]. Users should upgrade to the latest firmware. No workaround is documented; the only remediation is applying the update.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.