7.5

CVE-2016-9344

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaMiineport E1 Firmware Version <= 1.7
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
MoxaMiineport E2 Firmware Version <= 1.3
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
MoxaMiineport E3 Firmware Version <= 1.0
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.519
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.