First published: Tue May 31 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Miineport E2 1242 Firmware | ||
Moxa Miineport E2 Firmware | =1.1 | |
Moxa Miineport E2 4561 Firmware | ||
Moxa Miineport E2 Firmware | =1.1 | |
Moxa MiiNePort E1 | ||
Moxa Miineport E1 7080 | =1.1.10 | |
Moxa Miineport E3 Firmware | ||
Moxa Miineport E3 | =1.0 | |
Moxa Miineport E1 4641 Firmware | ||
Moxa Miineport E1 4641 Firmware | =1.1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2285 has a medium severity rating due to its potential impact on user authorization.
To mitigate CVE-2016-2285, ensure that firmware for affected devices is updated to the latest version provided by Moxa.
CVE-2016-2285 affects Moxa MiiNePort E1 4641, E1 7080, E2 1242, and E2 4561 devices running specific firmware versions.
Yes, CVE-2016-2285 can be exploited remotely through cross-site request forgery.
CVE-2016-2285 is categorized as a cross-site request forgery (CSRF) vulnerability.