CVE-2016-5799

CRITICAL

Moxa OnCell G3001 Firmware < 1.6 and G3100V2 Firmware < 2.7 - Improper Authorization

Title source: llm
STIX 2.1

Description

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-236-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92606

Scores

CVSS v3 9.8
EPSS 0.0090
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-285
Status published
Products (2)
moxa/oncell_g3001_firmware < 1.6
moxa/oncell_g3100v2_firmware < 2.7
Published Aug 24, 2016
Tracked Since Feb 18, 2026