CVE-2016-9346

MEDIUM

Moxa MiiNePort E1 < 1.8, E2 < 1.4, E3 < 1.1 - Unprotected Configuration Data Exposure

Title source: llm
STIX 2.1

Description

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are stored in a file that is not encrypted.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-343-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94783

Scores

CVSS v3 5.3
EPSS 0.0016
EPSS Percentile 36.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-310
Status published
Products (4)
moxa/miineport_e1_firmware < 1.7
moxa/miineport_e2_firmware < 1.3
moxa/miineport_e3_firmware < 1.0
n/a/Moxa MiiNePort Moxa MiiNePort
Published Feb 13, 2017
Tracked Since Feb 18, 2026