CVE-2016-2285

Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:moxa:miineport_e2_1242:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:miineport_e2_1242_firmware:1.1:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:moxa:miineport_e2_4561:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:miineport_e2_4561_firmware:1.1:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:moxa:miineport_e1_7080:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:miineport_e1_7080_firmware:1.1.10:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:moxa:miineport_e3:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:miineport_e3_firmware:1.0:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:moxa:miineport_e1_4641:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:miineport_e1_4641_firmware:1.1.10:*:*:*:*:*:*:*

Information

Published : 2016-05-30 18:59

Updated : 2016-11-29 19:04


NVD link : CVE-2016-2285

Mitre link : CVE-2016-2285


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

moxa

  • miineport_e3
  • miineport_e2_1242_firmware
  • miineport_e2_4561_firmware
  • miineport_e1_4641_firmware
  • miineport_e3_firmware
  • miineport_e1_4641
  • miineport_e2_1242
  • miineport_e1_7080
  • miineport_e1_7080_firmware
  • miineport_e2_4561