Lucene search

K
nvd[email protected]NVD:CVE-2016-2275
HistoryFeb 21, 2016 - 5:59 a.m.

CVE-2016-2275

2016-02-2105:59:01
CWE-284
web.nvd.nist.gov
5

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

72.0%

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via modified JavaScript code.

Affected configurations

Nvd
Node
advantechvesp211-euMatch-
AND
advantechvesp211-eu_firmwareMatch1.7.2
Node
advantechvesp211-232Match-
AND
advantechvesp211-232_firmwareMatch1.5.1
OR
advantechvesp211-232_firmwareMatch1.7.2
VendorProductVersionCPE
advantechvesp211-eu-cpe:2.3:h:advantech:vesp211-eu:-:*:*:*:*:*:*:*
advantechvesp211-eu_firmware1.7.2cpe:2.3:a:advantech:vesp211-eu_firmware:1.7.2:*:*:*:*:*:*:*
advantechvesp211-232-cpe:2.3:h:advantech:vesp211-232:-:*:*:*:*:*:*:*
advantechvesp211-232_firmware1.5.1cpe:2.3:a:advantech:vesp211-232_firmware:1.5.1:*:*:*:*:*:*:*
advantechvesp211-232_firmware1.7.2cpe:2.3:a:advantech:vesp211-232_firmware:1.7.2:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

72.0%

Related for NVD:CVE-2016-2275