MEDIUM · 5.3

CVE-2016-2282

Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext ...

Vulnerability Description

Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

CVSS Score

5.3

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MoxaIoadmin Firmware<= 3.17
MoxaIologik Firmware<= 3.11
MoxaIologik E2210-
MoxaIologik E2210-T-
MoxaIologik E2212-
MoxaIologik E2212-T-
MoxaIologik E2214-
MoxaIologik E2214-T-
MoxaIologik E2240-
MoxaIologik E2240-T-
MoxaIologik E2242-
MoxaIologik E2242-T-
MoxaIologik E2260-
MoxaIologik E2260-T-
MoxaIologik E2262-
MoxaIologik E2262-T-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-2282?

CVE-2016-2282 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext ...

How severe is CVE-2016-2282?

CVE-2016-2282 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-2282?

Check the references section above for vendor advisories and patch information. Affected products include: Moxa Ioadmin Firmware, Moxa Iologik Firmware, Moxa Iologik E2210, Moxa Iologik E2210-T, Moxa Iologik E2212.