First published: Mon Feb 13 2017(Updated: )
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. An attacker can freely use brute force to determine parameters needed to bypass authentication.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Nport 5100a Series Firmware | <=2.5 | |
MOXA NPort | ||
Moxa Nport 5100a Series Firmware | <=3.5 | |
Moxa Nport 5130A-T | ||
Moxa NPort 5150 | ||
Moxa NPort 5200 Series Firmware | <=2.7 | |
Moxa NPort 5210-T | ||
Moxa NPort 5230 | ||
Moxa NPort 5232 Firmware | ||
Moxa NPort 5232i | ||
Moxa NPort 5400 Series Firmware | <=3.10 | |
Moxa Nport 5410 Firmware | ||
Moxa NPort 5430i | ||
Moxa NPort 5430i | ||
Moxa Nport 5450 Firmware | ||
Moxa NPort 5450-T Firmware | ||
Moxa NPort 5450i Firmware | ||
Moxa NPort 5450i | ||
Moxa NPort 5600-8-dtl Series Firmware | <=3.6 | |
Moxa NPort 5610-16 Firmware | ||
Moxa NPort 5630-8 Firmware | ||
Moxa NPort 5650-16 | ||
Moxa NPort 5100A Firmware | <=1.2 | |
Moxa NPort P5110A | ||
Moxa NPort 5130A Firmware | ||
Moxa NPort P5150A-T | ||
Moxa NPort P5150A Series Firmware | <=1.2 | |
Moxa NPort 5110A-T | ||
Moxa Nport 5200 Series Firmware | <=1.2 | |
Moxa NPort 5210A-T Firmware | ||
Moxa NPort 5230A-T | ||
Moxa NPort 5250A Firmware | ||
Moxa NPort 5x50a1-m12 Series Firmware | <=1.1 | |
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5150AI-M12-CT | ||
Moxa NPort 5150A1-M12-CT | ||
Moxa NPort 5150A1-M12-T | ||
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5250A1-M12-CT | ||
Moxa NPort 5250A1-M12-T | ||
Moxa NPort 5250A1-M12-CT-T | ||
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5450A1-M12 | ||
Moxa NPort 5450A1-M12-CT-T | ||
Moxa NPort 5450A1-M12-T | ||
Moxa NPort 5600 Series Firmware | <=2.3 | |
Moxa NPort 5610-8 | ||
Moxa NPort 5650 Series | ||
Moxa NPort 5650i-8-DTL | ||
Moxa NPort 6100 Series Firmware | <=1.13 | |
Moxa NPort 6150-T | ||
Moxa NPort 6150-T Firmware | ||
All of | ||
Moxa Nport 5100a Series Firmware | <=2.5 | |
MOXA NPort | ||
All of | ||
Moxa Nport 5100a Series Firmware | <=3.5 | |
Any of | ||
Moxa Nport 5130A-T | ||
Moxa NPort 5150 | ||
All of | ||
Moxa NPort 5200 Series Firmware | <=2.7 | |
Any of | ||
Moxa NPort 5210-T | ||
Moxa NPort 5230 | ||
Moxa NPort 5232 Firmware | ||
Moxa NPort 5232i | ||
All of | ||
Moxa NPort 5400 Series Firmware | <=3.10 | |
Any of | ||
Moxa Nport 5410 Firmware | ||
Moxa NPort 5430i | ||
Moxa NPort 5430i | ||
Moxa Nport 5450 Firmware | ||
Moxa NPort 5450-T Firmware | ||
Moxa NPort 5450i Firmware | ||
Moxa NPort 5450i | ||
All of | ||
Moxa NPort 5600-8-dtl Series Firmware | <=3.6 | |
Any of | ||
Moxa NPort 5610-16 Firmware | ||
Moxa NPort 5630-8 Firmware | ||
Moxa NPort 5650-16 | ||
All of | ||
Moxa NPort 5100A Firmware | <=1.2 | |
Any of | ||
Moxa NPort P5110A | ||
Moxa NPort 5130A Firmware | ||
Moxa NPort P5150A-T | ||
All of | ||
Moxa NPort P5150A Series Firmware | <=1.2 | |
Moxa NPort 5110A-T | ||
All of | ||
Moxa Nport 5200 Series Firmware | <=1.2 | |
Any of | ||
Moxa NPort 5210A-T Firmware | ||
Moxa NPort 5230A-T | ||
Moxa NPort 5250A Firmware | ||
All of | ||
Moxa NPort 5x50a1-m12 Series Firmware | <=1.1 | |
Any of | ||
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5150AI-M12-CT | ||
Moxa NPort 5150A1-M12-CT | ||
Moxa NPort 5150A1-M12-T | ||
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5250A1-M12-CT | ||
Moxa NPort 5250A1-M12-T | ||
Moxa NPort 5250A1-M12-CT-T | ||
Moxa NPort 5x50a1-m12 Series Firmware | ||
Moxa NPort 5450A1-M12 | ||
Moxa NPort 5450A1-M12-CT-T | ||
Moxa NPort 5450A1-M12-T | ||
All of | ||
Moxa NPort 5600 Series Firmware | <=2.3 | |
Any of | ||
Moxa NPort 5610-8 | ||
Moxa NPort 5650 Series | ||
Moxa NPort 5650i-8-DTL | ||
All of | ||
Moxa NPort 6100 Series Firmware | <=1.13 | |
Any of | ||
Moxa NPort 6150-T | ||
Moxa NPort 6150-T Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9366 is classified as a high severity vulnerability affecting Moxa NPort devices due to insufficient access controls.
To fix CVE-2016-9366, update your Moxa NPort device firmware to the following versions or later: NPort 5110 to 2.6, NPort 5130/5150 to 3.6, NPort 5200 to 2.8, NPort 5400 to 3.11, and NPort 5600 to 3.7.
Devices affected by CVE-2016-9366 include Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series prior to 3.6, and several other Moxa NPort models across different series.
There is no public information indicating that CVE-2016-9366 is actively exploited in the wild at this time.
The potential impacts of CVE-2016-9366 include unauthorized access to device configurations and sensitive data, leading to risks in network security.