ID

VAR-201605-0034


CVE

CVE-2016-2311


TITLE

Black Box AlertWerks ServSensor Vulnerability to obtain administrator and user passwords in product firmware

Trust: 0.8

sources: JVNDB: JVNDB-2016-002966

DESCRIPTION

Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact with firmware before SP473 allow remote authenticated users to discover administrator and user passwords via unspecified vectors. Black Box AlertWerks ServSensor is prone to an information-disclosure vulnerability. An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks. AlertWerks ServSensor is a core product for environmental monitoring system; AlertWerks ServSensor Junior is a remote environmental monitoring host product. The following models and versions are affected: Black Box AlertWerks ServSensor, EME105A, EME106A, EME108A-R2, EME109A-R2, EME110A-R2, AlertWerks ServSensor Junior, EME102A-R2, EME103A-R2, EME104A-R2, ServSensor Junior with PoE, EME152A, EME153A, EME154A, EME155A, EME158A, AlertWerks ServSensor Contact, EME111A-20-R2, EME111A?60-R2, EME112A-20-R2, EME112A-60-R2, EME113A, EME132A-20-R ?60-R2

Trust: 1.98

sources: NVD: CVE-2016-2311 // JVNDB: JVNDB-2016-002966 // BID: 90899 // VULHUB: VHN-91130

IOT TAXONOMY

category:['network device']sub_category:gateway

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:blackboxmodel:alertwerks servsensor juniorscope:eqversion: -

Trust: 1.0

vendor:blackboxmodel:alertwerks servsensorscope:eqversion: -

Trust: 1.0

vendor:blackboxmodel:alertwerks servsensor contactscope:eqversion: -

Trust: 1.0

vendor:black box network servicesmodel:alertwerks servsensorscope: - version: -

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor contactscope: - version: -

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor contactscope:ltversion:sp473

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor juniorscope:eqversion:none

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor juniorscope:eqversion:with poe

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor juniorscope:ltversion:sp473

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensor juniorscope:ltversion:sp473 (with poe)

Trust: 0.8

vendor:black box network servicesmodel:alertwerks servsensorscope:ltversion:sp473

Trust: 0.8

vendor:blackboxmodel:alertwerks servsensor junior eme152ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor eme108a-r2scope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor junior eme155ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor eme106ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor junior eme154ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor eme105ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor eme109a-r2scope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor junior eme158ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor junior eme153ascope:eqversion: -

Trust: 0.6

vendor:blackboxmodel:alertwerks servsensor eme110a-r2scope:eqversion: -

Trust: 0.6

sources: JVNDB: JVNDB-2016-002966 // CNNVD: CNNVD-201605-652 // NVD: CVE-2016-2311

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-2311
value: MEDIUM

Trust: 1.0

NVD: CVE-2016-2311
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201605-652
value: MEDIUM

Trust: 0.6

VULHUB: VHN-91130
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2016-2311
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-91130
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-2311
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-91130 // JVNDB: JVNDB-2016-002966 // CNNVD: CNNVD-201605-652 // NVD: CVE-2016-2311

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-91130 // JVNDB: JVNDB-2016-002966 // NVD: CVE-2016-2311

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201605-652

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201605-652

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-002966

PATCH

title:AlertWerksurl:https://www.blackbox.co.jp/ja-jp/s///AlertWerks

Trust: 0.8

title:Multiple Black Box AlertWerks ServSensor Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=61962

Trust: 0.6

sources: JVNDB: JVNDB-2016-002966 // CNNVD: CNNVD-201605-652

EXTERNAL IDS

db:NVDid:CVE-2016-2311

Trust: 2.9

db:ICS CERTid:ICSA-16-147-03

Trust: 2.5

db:JVNDBid:JVNDB-2016-002966

Trust: 0.8

db:CNNVDid:CNNVD-201605-652

Trust: 0.7

db:BIDid:90899

Trust: 0.4

db:OTHERid:NONE

Trust: 0.1

db:VULHUBid:VHN-91130

Trust: 0.1

sources: OTHER: None // VULHUB: VHN-91130 // BID: 90899 // JVNDB: JVNDB-2016-002966 // CNNVD: CNNVD-201605-652 // NVD: CVE-2016-2311

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-16-147-03

Trust: 2.5

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-2311

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-2311

Trust: 0.8

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // VULHUB: VHN-91130 // JVNDB: JVNDB-2016-002966 // CNNVD: CNNVD-201605-652 // NVD: CVE-2016-2311

CREDITS

Lee Ryman

Trust: 0.3

sources: BID: 90899

SOURCES

db:OTHERid: -
db:VULHUBid:VHN-91130
db:BIDid:90899
db:JVNDBid:JVNDB-2016-002966
db:CNNVDid:CNNVD-201605-652
db:NVDid:CVE-2016-2311

LAST UPDATE DATE

2025-04-13T22:17:36.594000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-91130date:2017-04-07T00:00:00
db:BIDid:90899date:2016-05-26T00:00:00
db:JVNDBid:JVNDB-2016-002966date:2016-06-02T00:00:00
db:CNNVDid:CNNVD-201605-652date:2016-05-31T00:00:00
db:NVDid:CVE-2016-2311date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-91130date:2016-05-30T00:00:00
db:BIDid:90899date:2016-05-26T00:00:00
db:JVNDBid:JVNDB-2016-002966date:2016-06-02T00:00:00
db:CNNVDid:CNNVD-201605-652date:2016-05-27T00:00:00
db:NVDid:CVE-2016-2311date:2016-05-30T01:59:06.003