Vulnerability Description
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | Vesp211-Eu | - |
| Advantech | Vesp211-Eu Firmware | 1.7.2 |
| Advantech | Vesp211-232 | - |
| Advantech | Vesp211-232 Firmware | 1.5.1 |
Related Weaknesses (CWE)
References
- https://ics-cert.us-cert.gov/advisories/ICSA-16-049-01Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-16-049-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2016-2275?
CVE-2016-2275 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows...
How severe is CVE-2016-2275?
CVE-2016-2275 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2275?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech Vesp211-Eu, Advantech Vesp211-Eu Firmware, Advantech Vesp211-232, Advantech Vesp211-232 Firmware.