Multiple web server vulnerabilities have been found in the OnCell G3470A-LTE Series version 1.7.7 and prior. These vulnerabilities stem from insufficient input validation and trust in the format string from an external source. An attacker could exploit these vulnerabilities by sending crafted input to the web service. Successful exploitation of these vulnerabilities could lead to a denial-of-service attack, remote code execution, and information disclosure.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper neutralization of special elements used in a command (CWE-77) CVE-2024-4638 |
An attacker can execute unauthorized commands. |
| 2 |
Improper neutralization of special elements used in a command (CWE-77) CVE-2024-4639 |
Malicious users can execute unauthorized commands. |
| 3 |
Buffercopy without checking size of input (Classic Buffer Overflow)(CWE-120) CVE-2024-4640 |
An attacker can write past the boundaries of allocated buffer regions in the memory, causing a program crash. |
| 4 |
Use of externally-controlled format string (CWE-134) CVE-2024-4641 |
An attacker could change an externally controlled format string to cause a memory leak and denial-of-service attack. |
Vulnerability Scoring Details
|
ID
|
CVSS
|
Vector
|
Remote Exploit without Auth?
|
|---|---|---|---|
| CVE-2024-4638 |
7.1 |
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | No |
| CVE-2024-4639 | 7.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N | No |
| CVE-2024-4640 | 7.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H | No |
| CVE-2024-4641 | 6.3 | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L | No |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-oncell-g3470a-lte-series-multiple-web-application-vulnerabilities