CVE-2016-8372
published 2017-02-13CVE-2016-8372: An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version…
PriorityP346high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.70%
74.6th percentile
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V3.13, and ioLogik E2262, firmware versions prior to V3.12. A password is transmitted in a format that is not sufficiently secure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | iologik_e1200_series_firmware | <= 2.4 | — |
| moxa | iologik_e1200_series_firmware | <= 2.3 | — |
| moxa | iologik_e1200_series_firmware | <= 2.5 | — |
| moxa | iologik_e2200_series_firmware | <= 3.11 | — |
| moxa | iologik_e2200_series_firmware | <= 3.12 | — |
| moxa | iologik_e2200_series_firmware | <= 3.13 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj28-3rh7-h4qv: An issue was discovered in Moxa ioLogik E1210, firmware Version V2
ghsa_unreviewed·2022-05-13
CVE-2016-8372 [HIGH] GHSA-mj28-3rh7-h4qv: An issue was discovered in Moxa ioLogik E1210, firmware Version V2
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version V2.4 and prior, ioLogik E1240, firmware Version V2.3 and prior, ioLogik E1241, firmware Version V2.4 and prior, ioLogik E1242, firmware Version V2.4 and prior, ioLogik E1260, firmware Version V2.4 and prior, ioLogik E1262, firmware Version V2.4 and prior, ioLogik E2210, firmware versions prior to V3.13, ioLogik E2212, firmware versions prior to V3.14, ioLogik E2214, firmware versions prior to V3.12, ioLogik E2240, firmware versions prior to V3.12, ioLogik E2242, firmware versions prior to V3.12, ioLogik E2260, firmware versions prior to V
CISA ICS
Moxa ioLogik E1200 Series Vulnerabilities (Update A)
cisa_ics·2016-10-13
Moxa ioLogik E1200 Series Vulnerabilities (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa ioLogik E1200 Series Vulnerabilities (Update A)
Last RevisedJanuary 31, 2017
Alert CodeICSA-16-287-05A
## OVERVIEW
This updated advisory is a follow-up to the original advisory titled ICSA-16-287-05 Moxa ioLogik E1200 Series Vulnerabilities that was published October 13, 2016, on the NCCIC/ICS-CERT web site.
## --------- Begin Update A Part 1 of 4 --------
Alexandru Ariciu of Applied Risk has identified vulnerabilities in Moxa’s ioLogik E1200 series and ioLogik E2200 series devices. Moxa has produced a new edition of the firmware to mitigate these vulnerabilities. Alexand
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published