PT-2017-9639 · Moxa · Awk-1121+18

Maxim Rupp

·

Published

2017-02-13

·

Updated

2017-03-16

·

CVE-2016-8362

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moxa OnCell OnCellG3470A-LTE versions (affected versions not specified) Moxa AWK-1131A/3131A/4131A Series versions (affected versions not specified) Moxa AWK-3191 Series versions (affected versions not specified) Moxa AWK-5232/6232 Series versions (affected versions not specified) Moxa AWK-1121/1127 Series versions (affected versions not specified) Moxa WAC-1001 V2 Series versions (affected versions not specified) Moxa WAC-2004 Series versions (affected versions not specified) Moxa AWK-3121-M12-RTG Series versions (affected versions not specified) Moxa AWK-3131-M12-RCC Series versions (affected versions not specified) Moxa AWK-5232-M12-RCC Series versions (affected versions not specified) Moxa TAP-6226 Series versions (affected versions not specified) Moxa AWK-3121/4121 Series versions (affected versions not specified) Moxa AWK-3131/4131 Series versions (affected versions not specified) Moxa AWK-5222/6222 Series versions (affected versions not specified)
Description An issue was discovered that allows any user to download log files by accessing a specific URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8362

Affected Products

Awk-1121
Awk-1127
Awk-1131A
Awk-3121
Awk-3121-M12-Rtg
Awk-3131-M12-Rcc
Awk-3131A
Awk-3191
Awk-4121
Awk-4131A
Awk-5222
Awk-5232
Awk-5232-M12-Rcc
Awk-6222
Awk-6232
Oncellg3470A-Lte
Tap-6226
Wac-1001 V2
Wac-2004