ZeroHour

CVE-2016-8712

PoC
CVSS 3.1
8.1 high
EPSS
1%p70
Published
()
Modified
Description

An exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1. The device uses one nonce for all session authentication requests and only changes the nonce if the web application has been idle for 300 seconds.

Vendors
moxa
Products
awk-3131a firmware
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news