Multiple product vulnerabilities were identified in Moxa’s OnCell G3100-HSPA Series and OnCell G3470A-LTE Series Cellular Gateway. In response to this, Moxa has developed related solutions to address these vulnerabilities.
The identified vulnerability types and potential impacts are shown below:
OnCell G3470A-LTE Series:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) CVE-2018-11425 |
Denial of service and remote code execution |
OnCell G3100-HSPA Series:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 | Uncontrolled Resource Consumption (CWE-400) CVE-2018-11420 |
Remote code execution |
| 2 | Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) CVE-2018-11423 |
Denial of service and remote code execution |
| 3 | Null Pointer Dereference (CWE-476) CVE-2018-11424 |
Denial of service |
| 4 | Improper Authentication (CWE-287) CVE-2018-11426 |
Attacker can brute force authentication parameters |
| 5 | Cross-Site Request Forgery (CSRF) (CWE-352) CVE-2018-11427 |
Attacker can impersonate administrative actions via web interface |
| 6 | Information Exposure (CWE-200) CVE-2018-11421 |
Attacker can obtain sensitive information such as administrative credentials |
| 7 | Improper Access Control (CWE-284) CVE-2018-11422 |
Attacker can modify configuration and upload firmware |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/oncell-g3100-hspa-oncell-g3470a-lte-cellular-gateway-vulnerabilities