CVE-2016-4816

CVSS V2 Medium 4.3 CVSS V3 Medium 6.5
Description
BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.
Overview
  • CVE ID
  • CVE-2016-4816
  • Assigner
  • vultures@jpcert.or.jp
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2016-06-19T01:59:11
  • Last Modified Date
  • 2016-06-21T13:09:59
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
AND
cpe:2.3:h:buffalo:wzr-600dhp3:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-600dhp3_firmware:*:*:*:*:*:*:*:* 1 OR 2.16
AND
cpe:2.3:h:buffalo:hw-450hp-zwe:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:*:*:*:*:*:*:*:* 1 OR 1.91
AND
cpe:2.3:h:buffalo:wzr-hp-g450h:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-hp-g450h_firmware:*:*:*:*:*:*:*:* 1 OR 1.87
AND
cpe:2.3:h:buffalo:wzr-450hp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-450hp_firmware:*:*:*:*:*:*:*:* 1 OR 1.97
AND
cpe:2.3:h:buffalo:wzr-900dhp2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-900dhp2_firmware:*:*:*:*:*:*:*:* 1 OR 2.16
AND
cpe:2.3:h:buffalo:wcr-300:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wcr-300_firmware:*:*:*:*:*:*:*:* 1 OR 1.86
AND
cpe:2.3:h:buffalo:wzr-450hp-cwt:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-450hp-cwt_firmware:*:*:*:*:*:*:*:* 1 OR 1.92
AND
cpe:2.3:h:buffalo:wzr-hp-g301nh:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-hp-g301nh_firmware:*:*:*:*:*:*:*:* 1 OR 1.81
AND
cpe:2.3:h:buffalo:wxr-1750dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wxr-1750dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.42
AND
cpe:2.3:h:buffalo:wzr-600dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-600dhp_firmware:1.97:*:*:*:*:*:*:* 1 OR
AND
cpe:2.3:h:buffalo:wzr-1750dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-1750dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.28
AND
cpe:2.3:h:buffalo:wzr-s1750dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-s1750dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.28
AND
cpe:2.3:h:buffalo:whr-300:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:whr-300_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wzr-s600dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-s600dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.16
AND
cpe:2.3:h:buffalo:wzr-hp-g302h:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-hp-g302h_firmware:*:*:*:*:*:*:*:* 1 OR 1.83
AND
cpe:2.3:h:buffalo:wapm-ag300n:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wapm-ag300n_firmware:*:*:*:*:*:*:*:* 1 OR 2.62
AND
cpe:2.3:h:buffalo:wzr-hp-ag300h:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-hp-ag300h_firmware:*:*:*:*:*:*:*:* 1 OR 1.73
AND
cpe:2.3:h:buffalo:wzr-d1100h:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-d1100h_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wpl-05g300:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wpl-05g300_firmware:*:*:*:*:*:*:*:* 1 OR 1.86
AND
cpe:2.3:h:buffalo:wzr-s900dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-s900dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.16
AND
cpe:2.3:h:buffalo:dwr-hp-g300nh:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:*:*:*:*:*:*:*:* 1 OR 1.81
AND
cpe:2.3:h:buffalo:whr-300hp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:whr-300hp_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wzr-1750dhp2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-1750dhp2_firmware:*:*:*:*:*:*:*:* 1 OR 2.28
AND
cpe:2.3:h:buffalo:wzr-1166dhp2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-1166dhp2_firmware:*:*:*:*:*:*:*:* 1 OR 2.13
AND
cpe:2.3:h:buffalo:wzr-300hp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-300hp_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wapm-apg300n:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wapm-apg300n_firmware:*:*:*:*:*:*:*:* 1 OR 2.62
AND
cpe:2.3:h:buffalo:wzr-900dhp2:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-900dhp2_firmware:*:*:*:*:*:*:*:* 1 OR 1.13
AND
cpe:2.3:h:buffalo:wxr-1900dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wxr-1900dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.34
AND
cpe:2.3:h:buffalo:wzr-900dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-900dhp_firmware:*:*:*:*:*:*:*:* 1 OR 1.11
AND
cpe:2.3:h:buffalo:wzr-1166dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-1166dhp_firmware:*:*:*:*:*:*:*:* 1 OR 2.13
AND
cpe:2.3:h:buffalo:whr-hp-g300n:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:whr-hp-g300n_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:bhr-4grv:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:bhr-4grv_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wzr-450hp-ub:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-450hp-ub_firmware:*:*:*:*:*:*:*:* 1 OR 1.96
AND
cpe:2.3:h:buffalo:wzr-hp-g300nh:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:wzr-hp-g300nh_firmware:*:*:*:*:*:*:*:* 1 OR 1.81
AND
cpe:2.3:h:buffalo:fs-600dhp:-:*:*:*:*:*:*:* 0 OR
cpe:2.3:o:buffalo:fs-600dhp_firmware:*:*:*:*:*:*:*:* 1 OR 3.34
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:P/I:N/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • NONE
  • Availability Impact
  • NONE
  • Base Score
  • 4.3
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 2.9
CVSS Version 3
  • Version
  • 3.0
  • Vector String
  • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • NONE
  • Base Score
  • 6.5
  • Base Severity
  • MEDIUM
  • Exploitability Score
  • 2.8
  • Impact Score
  • 3.6
References
Reference URL Reference Tags
http://buffalo.jp/support_s/s20160527a.html Patch Vendor Advisory
http://jvn.jp/en/jp/JVN75813272/index.html Vendor Advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2016-000087 Vendor Advisory
History
Created Old Value New Value Data Type Notes
2022-05-10 10:15:45 Added to TrackCVE
2022-12-02 10:00:39 2016-06-19T01:59Z 2016-06-19T01:59:11 CVE Published Date updated
2022-12-02 10:00:39 2016-06-21T13:09:59 CVE Modified Date updated
2022-12-02 10:00:39 Analyzed Vulnerability Status updated