VulnerabilityModified
CVE-2016-9344
An attacker may be able to brute force an active session cookie to be able to download configuration files.
HIGH 7.5EPSS 1.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- moxa/miineport e1 firmware · moxa/miineport e2 firmware · moxa/miineport e3 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/94783Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-343-01Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/94783Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-16-343-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.