10
CVE-2016-2275
- EPSS 0.29%
- Published 21.02.2016 05:59:01
- Last modified 12.04.2025 10:46:40
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.
Data is provided by the National Vulnerability Database (NVD)
Advantech ≫ Vesp211-eu Firmware Version1.7.2
Advantech ≫ Vesp211-232 Firmware Version1.5.1
Advantech ≫ Vesp211-232 Firmware Version1.7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.497 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.