CVE-2016-2310

General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01 Third Party Advisory US Government Resource
https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ge:multilink_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ge:multilink_ml1200:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml1600:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml2400:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml800:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:h:ge:multilink_ml3000:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml3100:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:multilink_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:48

Type Values Removed Values Added
References () https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01 - Third Party Advisory, US Government Resource

Information

Published : 2016-06-09 10:59

Updated : 2024-11-21 02:48


NVD link : CVE-2016-2310

Mitre link : CVE-2016-2310

CVE.ORG link : CVE-2016-2310


JSON object : View

Products Affected

ge

  • multilink_firmware
  • multilink_ml1600
  • multilink_ml2400
  • multilink_ml800
  • multilink_ml3000
  • multilink_ml810
  • multilink_ml1200
  • multilink_ml3100
CWE
CWE-798

Use of Hard-coded Credentials