CVE-2016-2310
Last modified
CVE-2016-2310 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.. EPSS estimates a 3.22% chance of exploitation in the next 30 days.
Description
General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ge | Multilink Firmware | <= 5.5.0 |
| Ge | Multilink Firmware | <= 5.5.0k |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2310?
How severe is CVE-2016-2310?
How do I fix CVE-2016-2310?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-2304Ecava IntegraXor before 5.0 build 4522 does not include the …
- CVE-2016-2305Cross-site scripting (XSS) vulnerability in Ecava IntegraXor…
- CVE-2016-2306The HMI web server in Ecava IntegraXor before 5.0 build 4522…
- CVE-2016-2307American Auto-Matrix Aspect-Nexus Building Automation Front-…
- CVE-2016-2308American Auto-Matrix Aspect-Nexus Building Automation Front-…
- CVE-2016-2309iRZ RUH2 before 2b does not validate firmware patches, which…
- CVE-2016-2311Black Box AlertWerks ServSensor with firmware before SP473, …
- CVE-2016-2312Turning all screens off in Plasma-workspace and kscreenlocke…
- CVE-2016-2313auth_login.php in Cacti before 0.8.8g allows remote authenti…
- CVE-2016-2314GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 de…
- CVE-2016-2315revision.c in git before 2.7.4 uses an incorrect integer dat…9.8
- CVE-2016-2316chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1,…
Are you affected by CVE-2016-2310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
