7.5

CVE-2016-9344

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaMiineport E1 Firmware Version <= 1.7
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
MoxaMiineport E2 Firmware Version <= 1.3
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
MoxaMiineport E3 Firmware Version <= 1.0
   MoxaMiineport E1 Version-
   MoxaMiineport E2 Version-
   MoxaMiineport E3 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.63% 0.732
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

http://www.securityfocus.com/bid/94783
Third Party Advisory
VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-343-01
Third Party Advisory
US Government Resource