Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Moxa
Subscribe
|
Miineport E1 4641
Subscribe
Miineport E1 4641 Firmware
Subscribe
Miineport E1 7080
Subscribe
Miineport E1 7080 Firmware
Subscribe
Miineport E2 1242
Subscribe
Miineport E2 1242 Firmware
Subscribe
Miineport E2 4561
Subscribe
Miineport E2 4561 Firmware
Subscribe
Miineport E3
Subscribe
Miineport E3 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-3369 | Cross-site request forgery (CSRF) vulnerability on Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 devices with firmware 1.1 Build 10080614, MiiNePort_E2_4561 devices with firmware 1.1 Build 10080614, and MiiNePort E3 devices with firmware 1.0 Build 11071409 allows remote attackers to hijack the authentication of arbitrary users. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T23:24:48.340Z
Reserved: 2016-02-09T00:00:00.000Z
Link: CVE-2016-2285
No data.
Status : Deferred
Published: 2016-05-31T01:59:04.930
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-2285
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD