CVE-2016-5799
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected (2)
Products: Moxa: Oncell G3001 Firmware, Oncell G3100v2 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.6 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3111 | All versions |
Moxa Oncell G3151 | All versions |
Moxa Oncell G3211 | All versions |
Moxa Oncell G3251 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.7 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3100v2 | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource
Timeline
No history available yet.