ZeroHour

CVE-2016-2275

CVSS 3.0
9.8 critical
EPSS
3%p84
Published
()
Modified
Description

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.

Vendors
advantech
Products
vesp211-eu firmware, vesp211-232 firmware
Weakness
CWE-284
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.