Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. The protocol is vulnerable to remote unauthenticated disclosure of sensitive information, including the administrator's password. Under certain conditions, it's also possible to retrieve additional information, such as content of HTTP requests to the device, or the previously used password, due to memory leakages.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMoxa Oncell G3150 Hspa
HWMoxaall versionsMoxa Oncell G3150 Hspa Firmware
OSMoxa≤ 1.6Moxa Oncell G3150 Hspa T
HWMoxaall versionsMoxa Oncell G3150 Hspa T Firmware
OSMoxa≤ 1.6
Related vulnerabilities
Podatność Auth Bypass w Moxa OnCell G3100-HSPA — słaby parametr Cookie
Moxa OnCell G3100-HSPA — brak uwierzytelnienia i szyfrowania protokołu konfiguracyjnego
Uszkodzenie pamięci w interfejsie webowym Moxa OnCell G3100-HSPA
Moxa OnCell G3100-HSPA — pominięcie uwierzytelnienia przez brute force cookie
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 an...