CRITICAL · 9.8

CVE-2016-5799

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain acce...

Vulnerability Description

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MoxaOncell G3001 Firmware<= 1.6
MoxaOncell G3111-
MoxaOncell G3151-
MoxaOncell G3211-
MoxaOncell G3251-
MoxaOncell G3100V2 Firmware<= 2.7
MoxaOncell G3100V2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-5799?

CVE-2016-5799 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which makes it easier for remote attackers to obtain acce...

How severe is CVE-2016-5799?

CVE-2016-5799 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2016-5799?

Check the references section above for vendor advisories and patch information. Affected products include: Moxa Oncell G3001 Firmware, Moxa Oncell G3111, Moxa Oncell G3151, Moxa Oncell G3211, Moxa Oncell G3251.