PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-9346 Moxa CVE debrief

CVE-2016-9346 is an information-disclosure issue in Moxa MiiNePort firmware. According to NVD, affected devices are MiiNePort E1 firmware prior to 1.8, E2 prior to 1.4, and E3 prior to 1.1, where configuration data are stored in a file without encryption. The published CVSS v3.0 score is 5.3 (Medium), reflecting a confidentiality impact only.

Vendor
Moxa
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2016-09-11
Original CVE updated
2025-06-17
Advisory published
2016-09-11
Advisory updated
2025-06-17

Who should care

ICS/OT administrators and asset owners running Moxa MiiNePort E1, E2, or E3 devices, especially teams that manage firmware updates, device backups, or filesystem access controls.

Technical summary

NVD classifies the weakness as CWE-310 and rates it CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The core issue is that configuration data are stored in an unencrypted file, which can expose sensitive device settings if the file is accessed. The affected firmware thresholds listed in the CVE record are E1 < 1.8, E2 < 1.4, and E3 < 1.1.

Defensive priority

Medium — remediate during normal maintenance cycles, with higher urgency if the devices are reachable by untrusted users or if their configuration files are exposed in backups or shared storage.

Recommended defensive actions

  • Upgrade MiiNePort E1 firmware to 1.8 or later, E2 to 1.4 or later, and E3 to 1.1 or later.
  • Restrict access to the device file system, configuration exports, and any backups that may contain the unencrypted configuration file.
  • Review where configuration files are stored and copied, and remove unnecessary access from shared or exposed locations.
  • Segment and monitor OT/ICS management access so only authorized administrators can reach the affected devices.
  • Validate remediation against the NVD and US-CERT advisory references listed for this CVE.

Evidence notes

The source corpus identifies the issue as CVE-2016-9346, published on 2017-02-13. NVD lists the affected firmware ranges for MiiNePort E1/E2/E3, the CVSS v3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, and CWE-310. NVD also references US-CERT advisory ICSA-16-343-01 and SecurityFocus BID 94783.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-9346 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-9346

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-9346 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9346

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.