CVE-2016-8716
Last modified
CVE-2016-8716 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.
Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Awk-3131a Firmware | 1.1 |
References
- http://www.talosintelligence.com/reports/TALOS-2016-0230Exploit, Mitigation, Third Party Advisory
- http://www.talosintelligence.com/reports/TALOS-2016-0230Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8716?
How severe is CVE-2016-8716?
How do I fix CVE-2016-8716?
Are you affected by CVE-2016-8716?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
