7.5

CVE-2016-2286

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 have a blank default password, which allows remote attackers to obtain access via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Miineport E2 1242 Firmware Version 1.1
   Moxa ≫ Miineport E2 1242 Version -
Moxa ≫ Miineport E1 7080 Firmware Version 1.1.10
   Moxa ≫ Miineport E1 7080 Version -
Moxa ≫ Miineport E2 4561 Firmware Version 1.1
   Moxa ≫ Miineport E2 4561 Version -
Moxa ≫ Miineport E3 Firmware Version 1.0
   Moxa ≫ Miineport E3 Version -
Moxa ≫ Miineport E1 4641 Firmware Version 1.1.10
   Moxa ≫ Miineport E1 4641 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.695
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://seclists.org/fulldisclosure/2016/May/7
https://ics-cert.us-cert.gov/advisories/ICSA-16-145-01
Third Party Advisory
US Government Resource