PatchSiren cyber security CVE debrief
CVE-2016-8360 Moxa CVE debrief
CVE-2016-8360 describes a double free condition in Moxa SoftCMS ASP Webserver that can be triggered by a specially crafted URL request. According to the CVE record, affected versions are SoftCMS prior to 1.6, and the impact may include denial of service or arbitrary code execution. The NVD record maps the weakness to CWE-415 and rates the issue HIGH with a network attack vector and no privileges or user interaction required.
- Vendor
- Moxa
- Product
- Softcms
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2016-08-21
- Original CVE updated
- 2025-06-05
- Advisory published
- 2016-08-21
- Advisory updated
- 2025-06-05
Who should care
Organizations running Moxa SoftCMS, especially in industrial or OT environments, should treat this as a high-priority vulnerability. Security teams responsible for externally reachable web services, plant network segmentation, and asset inventory should also review exposure.
Technical summary
The vulnerability is a double free in the SoftCMS ASP Webserver reachable through a crafted URL request. NVD identifies the weakness as CWE-415 and lists affected Moxa SoftCMS versions up to and including 1.5, with version 1.6 indicated as the fixed boundary in the CVE description. Because the issue is network-reachable and can affect memory management, it may be exploitable for service disruption and potentially code execution, depending on runtime conditions.
Defensive priority
High. The issue is remotely reachable and has high potential impact on confidentiality, integrity, and availability. Even with CVSS AC:H, the combination of no authentication, no user interaction, and possible code execution makes exposure worth urgent review.
Recommended defensive actions
- Inventory all Moxa SoftCMS deployments and determine whether any instance is running version 1.5 or earlier.
- Upgrade SoftCMS to version 1.6 or later, using vendor-supported remediation guidance where available.
- Restrict access to the SoftCMS ASP Webserver to trusted management networks only.
- Monitor webserver and application logs for unusual or malformed URL requests.
- Apply network segmentation and compensating controls for any systems that cannot be upgraded immediately.
- Validate that only authorized administrators can reach the management interface from the network.
- Track the NVD and official advisory references for any additional remediation details or product guidance.
Evidence notes
This debrief is based on the supplied CVE record and NVD metadata. The core vulnerability description comes from the CVE text in the source corpus. Affected versions are taken from the NVD CPE criteria indicating Moxa SoftCMS through 1.5. The weakness classification CWEs and CVSS vector are also taken from the NVD record. Official and government-linked references provided in the corpus include the CVE record, NVD detail page, and ICS-CERT advisory reference URLs.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-16-322-02
[email protected] - Mitigation, Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.