Multiple product vulnerabilities were identified in Moxa’s cellular management software OnCell Central Manager. The vulnerabilities are based on Apache Flex BlazeDS’s, a third-party component, that is embedded on the OnCell central manager. In response to this, Moxa has developed related solutions to address the vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Deserialization of Untrusted Data (CWE-502), CVE-2017-5641 | Remote code execution on third-party component: Apache Flex BlazeDS |
| 2 | Information Exposure (CWE-200), CVE-2015-3269 | XML External Entity (XXE) processing on third-party component: Apache Flex BlazeDS |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/oncell-central-manager-cellular-management-software-vulnerabilities