cbcvebase.
CVE-2016-8716
published 2017-04-12

CVE-2016-8716: An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running…

PriorityP339high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
0.83%
53.1th percentile
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.

Affected

2 ranges
VendorProductVersion rangeFixed in
moxaawk-3131a_firmware
moxaawk-3131a_series_industrial_ieee_802.11a_b_g_n_wireless_ap_bridge_client

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.