7.8

CVE-2021-46082

Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol gateways were discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaTn-5916-wv-t Firmware Version <= 3.1
   MoxaTn-5916-wv-t Version-
MoxaTn-5916-wv-ct-t Firmware Version <= 3.1
   MoxaTn-5916-wv-ct-t Version-
MoxaMgate 5109 Firmware Version <= 2.2
   MoxaMgate 5109 Version-
MoxaMgate 5109-t Firmware Version <= 2.2
   MoxaMgate 5109-t Version-
MoxaMgate 5101-pbm-mn Firmware Version <= 2.1
   MoxaMgate 5101-pbm-mn Version-
MoxaMgate 5101-pbm-mn-t Firmware Version <= 2.1
   MoxaMgate 5101-pbm-mn-t Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.638
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://www.moxa.com/en/support/product-support/security-advisory/mgate-5109-5101-protocol-gateways-vulnerability
Patch
Vendor Advisory
https://www.moxa.com/en/support/product-support/security-advisory/tn-5900-secure-routers-vulnerability
Vendor Advisory