CVE-2016-2289: Iconics Webhmi

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified vectors.

Affected products

  • Iconics Webhmi: up to and including 9.0

Published 2016-04-01. Last modified 2026-06-17.