Multiple vulnerabilities in Moxa OnCell G3100-HSPA Series



Published: 2018-03-02
Risk Low
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2018-5455
CVE-2018-5453
CVE-2018-5449
CWE-ID CWE-565
CWE-130
CWE-476
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
OnCell G3100-HSPA Series
Hardware solutions / Firmware

Vendor Moxa

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Brute-force attack

EUVDB-ID: #VU10813

Risk: Low

CVSSv3.1: 6.4 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-5455

CWE-ID: CWE-565 - Reliance on Cookies without Validation and Integrity Checking

Exploit availability: No

Description

The vulnerability allows remote attacker to perform brute-force attack on the target system.

The vulnerability exists due to the application allows a cookie parameter to consist of only digits. A remote attacker can perform a brute force attack, bypass authentication and gain access to device functions.

Successful exploitation of this vulnerability may result in unauthorized access to the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

OnCell G3100-HSPA Series: All versions

External links

http://ics-cert.us-cert.gov/advisories/ICSA-18-060-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Denial of service

EUVDB-ID: #VU10814

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-5453

CWE-ID: CWE-130 - Improper Handling of Length Parameter Inconsistency

Exploit availability: No

Description

The vulnerability allows remote attacker to cause DoS condition on the target system.

The vulnerability exists due to improper handling of length parameter inconsistency. A remote attacker can edit the element of an HTTP request and cause the device to become unavailable.

Mitigation

Install update from vendor's website.

Vulnerable software versions

OnCell G3100-HSPA Series: All versions

External links

http://ics-cert.us-cert.gov/advisories/ICSA-18-060-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Null pointer dereference

EUVDB-ID: #VU10815

Risk: Low

CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-5449

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows remote attacker to cause DoS condition on the target system.

The vulnerability exists due to the application does not check for a NULL value. A remote attacker can trigger NULL pointer dereference and cause the device to become unavailable.

Mitigation

Install update from vendor's website.

Vulnerable software versions

OnCell G3100-HSPA Series: All versions

External links

http://ics-cert.us-cert.gov/advisories/ICSA-18-060-02


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###