Weak Cookie Parameter in Moxa OnCell G3100-HSPA Series Affects Security
CVE-2018-11426
9.8CRITICAL
Summary
The Moxa OnCell G3100-HSPA Series web application uses weak cookie parameters that potentially allow an attacker to brute force these parameters. This exploitation can lead to unauthorized access to the web interface, enabling malicious users to utilize most functionalities without changing the password, thereby putting sensitive data and system integrity at risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved