OnCell G3470A-LTE Series Firmware Vulnerability
CVE-2024-4641

9.8CRITICAL

Key Information:

Vendor
Moxa
Status
Oncell G3150a-lte Series
Vendor
CVE Published:
25 June 2024

Summary

The OnCell G3470A-LTE Series firmware, particularly versions v1.7.7 and earlier, suffers from a vulnerability due to the improper handling of format strings from external sources. This flaw allows attackers to exploit the system by modifying an externally controlled format string, potentially leading to serious consequences such as memory leaks and subsequent denial of service. Users of affected firmware are recommended to review their systems and apply necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

OnCell G3150A-LTE Series 1.0 <= 1.7.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Nikita Abramov from Positive Technologies
.