Unauthorized Command Execution Vulnerability in OnCell G3470A-LTE Series Firmware
CVE-2024-4639

8.8HIGH

Key Information:

Vendor
Moxa
Vendor
CVE Published:
25 June 2024

Summary

The OnCell G3470A-LTE Series from Moxa has a vulnerability stemming from improper handling of user inputs in its IPSec configuration. This oversight allows attackers to manipulate commands sent to critical functions within the device. By exploiting this flaw, malicious actors can execute commands that the device administrator did not intend, potentially compromising the integrity and security of the network environment. Users are advised to update to secure firmware versions to mitigate risks associated with this vulnerability.

Affected Version(s)

OnCell G3150A-LTE Series 1.0 <= 1.7.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nikita Abramov from Positive Technologies
.