协议网关的账户管理接口中存在基于栈的缓冲区溢出漏洞。该漏洞是由于在处理账户管理请求时,对 参数的长度验证不足所致。攻击者如果以只读用户身份认证到 Web 管理界面,即可提交一个特别构造的、超出内部栈缓冲区大小的账户名,从而导致程序执行流被破坏。成功利用此漏洞可能使攻击者能够从设备内存中读取敏感信息(包括凭据),修改任意内存内容,并破坏设备的可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Moxa | MGate MB3170 Series | 1.0≤ 4.7 |
affected |
| Moxa | MGate MB3270 Series | 1.0≤ 4.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moxa | MGate MB3170 Series | 1.0 ~ 4.7 | - |
|
| Moxa | MGate MB3270 Series | 1.0 ~ 4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet