8.8

CVE-2016-9365

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4.  Requests are not verified to be intentionally submitted by the proper user (CROSS-SITE REQUEST FORGERY).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MoxaNport 5100 Series Firmware Version <= 2.5
   MoxaNport 5110 Version-
MoxaNport 5100 Series Firmware Version <= 3.5
   MoxaNport 5130 Version-
   MoxaNport 5150 Version-
MoxaNport 5200 Series Firmware Version <= 2.7
   MoxaNport 5210 Version-
   MoxaNport 5230 Version-
   MoxaNport 5232 Version-
   MoxaNport 5232i Version-
MoxaNport 5400 Series Firmware Version <= 3.10
   MoxaNport 5410 Version-
   MoxaNport 5430 Version-
   MoxaNport 5430i Version-
   MoxaNport 5450 Version-
   MoxaNport 5450-t Version-
   MoxaNport 5450i Version-
   MoxaNport 5450i-t Version-
MoxaNport 5600 Series Firmware Version <= 3.6
   MoxaNport 5610 Version-
   MoxaNport 5630 Version-
   MoxaNport 5650 Version-
MoxaNport 5100a Series Firmware Version <= 1.2
   MoxaNport 5110a Version-
   MoxaNport 5130a Version-
   MoxaNport 5150a Version-
MoxaNport P5150a Series Firmware Version <= 1.2
   MoxaNport P5110a Version-
MoxaNport 5200a Series Firmware Version <= 1.2
   MoxaNport 5210a Version-
   MoxaNport 5230a Version-
   MoxaNport 5250a Version-
MoxaNport 5x50a1-m12 Series Firmware Version <= 1.1
   MoxaNport 5150a1-m12 Version-
   MoxaNport 5150a1-m12-ct Version-
   MoxaNport 5150a1-m12-ct-t Version-
   MoxaNport 5150a1-m12-t Version-
   MoxaNport 5250a1-m12 Version-
   MoxaNport 5250a1-m12-ct Version-
   MoxaNport 5250a1-m12-ct-t Version-
   MoxaNport 5250a1-m12-t Version-
   MoxaNport 5450a1-m12 Version-
   MoxaNport 5450a1-m12-ct Version-
   MoxaNport 5450a1-m12-ct-t Version-
   MoxaNport 5450a1-m12-t Version-
MoxaNport 5600-8-dtl Series Firmware Version <= 2.3
   MoxaNport 5610-8-dtl Version-
   MoxaNport 5650-8-dtl Version-
   MoxaNport 5650i-8-dtl Version-
MoxaNport 6100 Series Firmware Version <= 1.13
   MoxaNport 6150 Version-
   MoxaNport 6150-t Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.278
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.