CVE-2021-33824
Last modified
CVE-2021-33824 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. EPSS estimates a 2.23% chance of exploitation in the next 30 days.
Description
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then the web server is denial-of-service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Moxa | Mgate Mb3180 Firmware | 2.1 | Build 18113012 |
References
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
- https://github.com/Jian-Xian/CVE-POC/blob/master/CVE-2021-33824.mdExploit, Third Party Advisory
- https://github.com/shekyan/slowhttptestThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-33824?
How severe is CVE-2021-33824?
How do I fix CVE-2021-33824?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-33816The website builder module in Dolibarr 13.0.2 allows remote …9.8
- CVE-2021-33818An issue was discovered in UniFi Protect G3 FLEX Camera Vers…7.5
- CVE-2021-3382Stack buffer overflow vulnerability in gitea 1.9.0 through 1…7.5
- CVE-2021-33820An issue was discovered in UniFi Protect G3 FLEX Camera Vers…7.5
- CVE-2021-33822An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E…7.5
- CVE-2021-33823An issue was discovered on MOXA Mgate MB3180 Version 2.1 Bui…7.5
- CVE-2021-33827The files_antivirus component before 1.0.0 for ownCloud allo…7.2
- CVE-2021-33828The files_antivirus component before 1.0.0 for ownCloud mish…8.8
- CVE-2021-33829A cross-site scripting (XSS) vulnerability in the HTML Data …6.1
- CVE-2021-33831api/account/register in the TH Wildau COVID-19 Contact Traci…6.5
- CVE-2021-33833ConnMan (aka Connection Manager) 1.30 through 1.39 has a sta…9.8
- CVE-2021-33834An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde…7.1
Are you affected by CVE-2021-33824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
