协议网关中存在加密签名验证不当的漏洞,因为设备在安装固件映像之前未正确验证其加密真实性。拥有高权限并能够访问固件更新接口的攻击者可以提供专门构造或篡改的固件映像,从而导致该映像被安装到设备上。成功利用此漏洞可能使攻击者能够执行未经授权的代码,破坏设备的完整性和可用性,并在后续固件更新中持久保留恶意修改。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Moxa | MGate MB3170 Series | 1.0 |
affected |
| Moxa | MGate MB3270 Series | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Moxa | MGate MB3170 Series | 1.0 | - |
|
| Moxa | MGate MB3270 Series | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet