Weak Cookie Parameter in Moxa OnCell G3100-HSPA Series Affects Security
CVE-2018-11426

9.8CRITICAL

Key Information:

Vendor
Moxa
Vendor
CVE Published:
3 July 2019

Summary

The Moxa OnCell G3100-HSPA Series web application uses weak cookie parameters that potentially allow an attacker to brute force these parameters. This exploitation can lead to unauthorized access to the web interface, enabling malicious users to utilize most functionalities without changing the password, thereby putting sensitive data and system integrity at risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.