CVE-2016-8363
10.0
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 6.0
Source: NVD
Description
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. User is able to execute arbitrary OS commands on the server.
Affected (14)
Products: Moxa: Oncellg3470a Lte Firmware, Awk 4131a Firmware, Awk 3191 Firmware, Awk 5232 Firmware, Awk 6232 Firmware, Awk 1121 Firmware, Awk 1127 Firmware, Wac 1001 V2 Firmware, Wac 2004 Firmware, Awk 3121 M12 Rtg Firmware, Awk 3131 M12 Rcc Firmware, Awk 5232 M12 Rcc Firmware, Awk 3131a Firmware, Awk 1131a Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10-31-2016 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncellg3470a Lte | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10-31-2016 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 4131a | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05-30-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 3191 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05-30-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 5232 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 05-30-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 6232 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 1121 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 1127 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Wac 1001 V2 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Wac 2004 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 3121 M12 Rtg | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 3131 M12 Rcc | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 06-29-2017 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 5232 M12 Rcc | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10-31-2016 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 3131a | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10-31-2016 |
| Running on/with | Platform Versions |
|---|---|
Moxa Awk 1131a | All versions |
Related CWEs
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.