NE-4100 Series and MiiNePort Series Affected by CVE-2016-9361

Published: October 21, 2024

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

This security advisory addresses CVE-2016-9361 affecting the NE-4100 Series, MiiNePort E1 Series, MiiNePort E2 Series, and MiiNePort E3 Series. The vulnerability allows an attacker to retrieve administration passwords without proper authentication. This flaw potentially compromises the security of the affected devices by enabling unauthorized access to administrative controls, allowing malicious actors to alter configurations or disrupt operations.

The Identified Vulnerability Type and Potential Impact

Item Vulnerability Type Impact
1

Improper Authentication (CWE-287)

CVE-2016-9361

The administration passwords can be retried without authenticating

Vulnerability Scoring Details 

ID
CVSS v3.0 
Vector
Severity

Unauthenticated

Remote Exploit

CVE-2016-9361

9.8

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Critical Yes

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241661-ne-4100-series-and-miineport-series-affected-by-cve-2016-9361