HIGH · 8.8

CVE-2016-9365

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort...

Vulnerability Description

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPort 5100A Series & NPort P5150A versions prior to 1.3, NPort 5200A Series versions prior to 1.3, NPort 5150AI-M12 Series versions prior to 1.2, NPort 5250AI-M12 Series versions prior to 1.2, NPort 5450AI-M12 Series versions prior to 1.2, NPort 5600-8-DT Series versions prior to 2.4, NPort 5600-8-DTL Series versions prior to 2.4, NPort 6x50 Series versions prior to 1.13.11, NPort IA5450A versions prior to v1.4. Requests are not verified to be intentionally submitted by the proper user (CROSS-SITE REQUEST FORGERY).

CVSS Score

8.8

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MoxaNport 5100 Series Firmware<= 2.5
MoxaNport 5110-
MoxaNport 5130-
MoxaNport 5150-
MoxaNport 5200 Series Firmware<= 2.7
MoxaNport 5210-
MoxaNport 5230-
MoxaNport 5232-
MoxaNport 5232I-
MoxaNport 5400 Series Firmware<= 3.10
MoxaNport 5410-
MoxaNport 5430-
MoxaNport 5430I-
MoxaNport 5450-
MoxaNport 5450-T-
MoxaNport 5450I-
MoxaNport 5450I-T-
MoxaNport 5600 Series Firmware<= 3.6
MoxaNport 5610-
MoxaNport 5630-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9365?

CVE-2016-9365 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort...

How severe is CVE-2016-9365?

CVE-2016-9365 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-9365?

Check the references section above for vendor advisories and patch information. Affected products include: Moxa Nport 5100 Series Firmware, Moxa Nport 5110, Moxa Nport 5130, Moxa Nport 5150, Moxa Nport 5200 Series Firmware.