Multiple product vulnerabilities were identified in Moxa’s ioLogik E1200 Series and ioLogik E2200 Series Controllers and I/O. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Multiple Stored Cross Site Scripting – XSS (CWE-79), CVE-2016-8359 | An authenticated user can execute arbitrary code from the web console. |
| 2 | Password sent via HTTP GET method (CWE-522), CVE-2016-8372 | In the HTTP web console, the password is not encrypted during the HTTP get request. |
| 3 | Password truncation (CWE-521), CVE-2016-8379 | With a brute force attack tool, it is possible to guess simple passwords. (e.g. password 12345678 or abcd1234) |
| 4 | Missing CSRF Protection (CWE-352), CVE-2016-8350 | An attacker may send requests by making a legitimate user click on a link. |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/iologik-e1200-series-and-iologik-e2200-series-controllers-and-io-vulnerabilities