CVE-2016-5799
CRITICALMoxa OnCell G3001 Firmware < 1.6 and G3100V2 Firmware < 2.7 - Improper Authorization
Title source: llmDescription
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
References (2)
Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-236-01
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/92606
Scores
CVSS v3
9.8
EPSS
0.0090
EPSS Percentile
75.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-285
Status
published
Products (2)
moxa/oncell_g3001_firmware
< 1.6
moxa/oncell_g3100v2_firmware
< 2.7
Published
Aug 24, 2016
Tracked Since
Feb 18, 2026