CVE-2016-5819
published 2019-03-21CVE-2016-5819: Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.89%
55.0th percentile
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | oncell_g3100v2_firmware | < 2.8 | 2.8 |
| moxa | oncell_g3100v2_series | < 2.8 | 2.8 |
| moxa | oncell_g3111_firmware | < 1.7 | 1.7 |
| moxa | oncell_g3111_g3151_g3211_g3251_series | < 1.7 | 1.7 |
| moxa | oncell_g3151_firmware | < 1.7 | 1.7 |
| moxa | oncell_g3211_firmware | < 1.7 | 1.7 |
| moxa | oncell_g3251_firmware | < 1.7 | 1.7 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jw53-g5p8-77fr: Moxa G3100V2 Series, editions prior to Version 2
ghsa_unreviewed·2022-05-13
CVE-2016-5819 [MEDIUM] CWE-79 GHSA-jw53-g5p8-77fr: Moxa G3100V2 Series, editions prior to Version 2
Moxa G3100V2 Series, editions prior to Version 2.8, and OnCell G3111/G3151/G3211/G3251 Series, editions prior to Version 1.7 allows a reflected cross-site scripting attack which may allow an attacker to execute arbitrary script code in the user’s browser within the trust relationship between their browser and the server.
CISA ICS
Moxa OnCell Vulnerabilities (Update A)
cisa_ics·2016-08-23
Moxa OnCell Vulnerabilities (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa OnCell Vulnerabilities (Update A)
Last RevisedAugust 23, 2018
Alert CodeICSA-16-236-01A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-16-236-01 Moxa OnCell Vulnerabilities that was published August 23, 2016, on the NCCIC/ICS-CERT web site.
Independent researcher Maxim Rupp has identified several vulnerabilities in Moxa’s OnCell products. Moxa has produced new firmware to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerability affects the following
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-03-21
Published