CVE-2016-2310

General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-16-154-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ge:multilink_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ge:multilink_ml1200:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml1600:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml2400:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml800:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:h:ge:multilink_ml3000:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml3100:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:multilink_firmware:*:*:*:*:*:*:*:*

History

29 Mar 2021, 18:06

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-798
CPE cpe:2.3:h:ge:ml3000_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml3100_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml810_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml2400_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml1200_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml800_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:ml1600_switch:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml1200:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml3000:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml3100:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml800:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml1600:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml810:-:*:*:*:*:*:*:*
cpe:2.3:h:ge:multilink_ml2400:-:*:*:*:*:*:*:*

Information

Published : 2016-06-09 10:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-2310

Mitre link : CVE-2016-2310

CVE.ORG link : CVE-2016-2310


JSON object : View

Products Affected

ge

  • multilink_ml800
  • multilink_ml3000
  • multilink_ml1600
  • multilink_ml3100
  • multilink_ml2400
  • multilink_ml1200
  • multilink_ml810
  • multilink_firmware
CWE
CWE-798

Use of Hard-coded Credentials