René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

166 lines
4.9 KiB
JSON

{
"id": "CVE-2016-5812",
"sourceIdentifier": "ics-cert@hq.dhs.gov",
"published": "2016-08-24T02:00:24.963",
"lastModified": "2016-11-28T20:29:36.613",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 use cleartext password storage, which makes it easier for local users to obtain sensitive information by reading a configuration file."
},
{
"lang": "es",
"value": "Dispositivos Moxa OnCell G3100V2 en versiones anteriores a 2.8 y dispositivos G3111, G3151, G3211 y G3251 en versiones anteriores a 1.7 utilizan un almacenamiento de contrase\u00f1as de texto sin cifrar, lo que facilita a usuarios locales obtener informaci\u00f3n sensible leyendo un archivo de configuraci\u00f3n."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 3.3,
"baseSeverity": "LOW"
},
"exploitabilityScore": 1.8,
"impactScore": 1.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:moxa:oncell_g3001_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.6",
"matchCriteriaId": "A47E15A8-95D4-4843-83F0-6C52872A9E66"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:moxa:oncell_g3111:-:*:*:*:*:*:*:*",
"matchCriteriaId": "3EBDEE8E-ADD2-471D-8DC9-E7FEAB6FCB85"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:moxa:oncell_g3151:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D13AE8D7-9DE6-44B7-8F14-3D8E75F49069"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:moxa:oncell_g3211:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8982D766-7245-4F31-BAD2-E75DCBDDFEC3"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:moxa:oncell_g3251:-:*:*:*:*:*:*:*",
"matchCriteriaId": "1DD3EA88-FD22-4CB1-A64F-84D0B9316ED8"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:moxa:oncell_g3100v2_firmware:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.7",
"matchCriteriaId": "E59A5E4D-7D6C-4D04-BE7B-A33D58F7460A"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:moxa:oncell_g3100v2:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A008AD02-4630-46E0-9F90-5078304C99A3"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/92605",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-16-236-01",
"source": "ics-cert@hq.dhs.gov",
"tags": [
"Mitigation",
"Third Party Advisory",
"US Government Resource"
]
}
]
}