10
CVSSv2

CVE-2016-2275

Published: 21/02/2016 Updated: 10/03/2016
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote malicious users to perform administrative actions via modified JavaScript code.

Vulnerable Product Search on Vulmon Subscribe to Product

advantech vesp211-eu_firmware 1.7.2

advantech vesp211-232_firmware 1.5.1

advantech vesp211-232_firmware 1.7.2