CVE-2016-2310
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.
Affected (2)
Products: Ge: Multilink Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.5.0 |
| Running on/with | Platform Versions |
|---|---|
Ge Multilink Ml1200 | All versions |
Ge Multilink Ml1600 | All versions |
Ge Multilink Ml2400 | All versions |
Ge Multilink Ml800 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.5.0k |
| Running on/with | Platform Versions |
|---|---|
Ge Multilink Ml3000 | All versions |
Ge Multilink Ml3100 | All versions |
Ge Multilink Ml810 | All versions |
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.