OnCell G3150A-LTE Series: Web Server Transmits Cleartext Credentials

CVE-2023-6094

5.3MEDIUM

Key Information

Vendor
Moxa
Status
Oncell G3150a-lte Series
Vendor
CVE Published:
31 December 2023

Summary

A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of attack could be executed to gather sensitive information or to facilitate a subsequent attack against the target.

Affected Version(s)

OnCell G3150A-LTE Series <= 1.3

Refferences

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.