CVE-2016-2289 is a directory traversal vulnerability affecting ICONICS WebHMI 9 and earlier, allowing remote attackers to read configuration files and potentially discover password hashes. This high-severity flaw (CVSS 7.5) is easily exploitable over the network with low complexity and no user interaction, leading to a high impact on confidentiality. While no public exploit code is available and it's not listed on the KEV catalog, there has been some community discussion and media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0CPE matchmatch criteria | cpe:2.3:a:iconics:webhmi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.