6.1
CVE-2016-5819
- EPSS 0.19%
- Veröffentlicht 21.03.2019 15:59:41
- Zuletzt bearbeitet 21.11.2024 02:55:04
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Oncell G3100v2 Firmware Version < 2.8
Moxa ≫ Oncell G3111 Firmware Version < 1.7
Moxa ≫ Oncell G3151 Firmware Version < 1.7
Moxa ≫ Oncell G3211 Firmware Version < 1.7
Moxa ≫ Oncell G3251 Firmware Version < 1.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.371 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.