CVE-2016-9344
published 2017-02-13CVE-2016-9344: An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.63%
73.5th percentile
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | miineport_e1_firmware | <= 1.7 | — |
| moxa | miineport_e2_firmware | <= 1.3 | — |
| moxa | miineport_e3_firmware | <= 1.0 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa MiiNePort Session Hijack Vulnerabilities
cisa_ics·2016-12-08
Moxa MiiNePort Session Hijack Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa MiiNePort Session Hijack Vulnerabilities
Last RevisedDecember 08, 2016
Alert CodeICSA-16-343-01
## OVERVIEW
Independent researcher Aditya Sood has identified vulnerabilities in Moxa’s MiiNePort. Moxa has produced new firmware editions to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
Moxa reports that the vulnerabilities affect the following versions of MiiNePort:
- MiiNePort E1 versions prior to 1.8,
- MiiNePort E2 versions prior to 1.4, and
- MiiNePort E3 versions prior to 1.1
## IMPACT
An attacker may be ab
GHSA
GHSA-wcmm-hvmm-f94r: An issue was discovered in Moxa MiiNePort E1 versions prior to 1
ghsa_unreviewed·2022-05-17
CVE-2016-9344 [HIGH] CWE-532 GHSA-wcmm-hvmm-f94r: An issue was discovered in Moxa MiiNePort E1 versions prior to 1
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published