ZeroHour

CVE-2016-2285

CVSS 3.0
8.8 high
EPSS
<1%p46
Published
()
Modified
Description

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.

Vendors
moxa
Products
miineport e2 1242 firmware, miineport e2 4561 firmware, miineport e1 7080 firmware, miineport e3 firmware, miineport e1 4641 firmware
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.