CVE-2016-2285

HIGH

Moxa MiiNePort E1/E2/E3 Firmware - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.

References (2)

Core 2
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/May/7
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-145-01

Scores

CVSS v3 8.8
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (5)
moxa/miineport_e1_4641_firmware 1.1.10
moxa/miineport_e1_7080_firmware 1.1.10
moxa/miineport_e2_1242_firmware 1.1
moxa/miineport_e2_4561_firmware 1.1
moxa/miineport_e3_firmware 1.0
Published May 31, 2016
Tracked Since Feb 18, 2026