CVE-2016-9367 Information
Description
An issue was discovered in Moxa NPort 5110 versions prior to 2.6 NPort 5130/5150 Series versions prior to 3.6 NPort 5200 Series versions prior to 2.8 NPort 5400 Series versions prior to 3.11 NPort 5600 Series versions prior to 3.7 NPort 5100A Series & NPort P5150A versions prior to 1.3 NPort 5200A Series versions prior to 1.3 NPort 5150AI-M12 Series versions prior to 1.2 NPort 5250AI-M12 Series versions prior to 1.2 NPort 5450AI-M12 Series versions prior to 1.2 NPort 5600-8-DT Series versions prior to 2.4 NPort 5600-8-DTL Series versions prior to 2.4 NPort 6x50 Series versions prior to 1.13.11 NPort IA5450A versions prior to v1.4. The amount of resources requested by a malicious actor is not restricted leading to a denial-of-service caused by resource exhaustion.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://www.securityfocus.com/bid/85965 https://ics-cert.us-cert.gov/advisories/ICSA-16-336-02
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: