6.5

CVE-2016-8362

An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. Any user is able to download log files by accessing a specific URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaOncellg3470a-lte Firmware Version <= 10-31-2016
   MoxaOncellg3470a-lte Version-
MoxaAwk-4131a Firmware Version <= 10-31-2016
   MoxaAwk-4131a Version-
MoxaAwk-3191 Firmware Version <= 05-30-2017
   MoxaAwk-3191 Version-
MoxaAwk-5232 Firmware Version <= 05-30-2017
   MoxaAwk-5232 Version-
MoxaAwk-6232 Firmware Version <= 05-30-2017
   MoxaAwk-6232 Version-
MoxaAwk-1121 Firmware Version <= 06-29-2017
   MoxaAwk-1121 Version-
MoxaAwk-1127 Firmware Version <= 06-29-2017
   MoxaAwk-1127 Version-
MoxaWac-1001 V2 Firmware Version <= 06-29-2017
   MoxaWac-1001 V2 Version-
MoxaWac-2004 Firmware Version <= 06-29-2017
   MoxaWac-2004 Version-
MoxaAwk-3121-m12-rtg Firmware Version <= 06-29-2017
   MoxaAwk-3121-m12-rtg Version-
MoxaAwk-3131-m12-rcc Firmware Version <= 06-29-2017
   MoxaAwk-3131-m12-rcc Version-
MoxaAwk-5232-m12-rcc Firmware Version <= 06-29-2017
   MoxaAwk-5232-m12-rcc Version-
MoxaAwk-3131a Firmware Version <= 10-31-2016
   MoxaAwk-3131a Version-
MoxaAwk-1131a Firmware Version <= 10-31-2016
   MoxaAwk-1131a Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.