CVE-2018-11422
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary configuration protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. Any commands (including device reboot, configuration download or upload, or firmware upgrade) are accepted and executed by the device without authentication.
Moxa OnCell G3100-HSPA Series versión 1.6 Build 17100315 y versiones anteriores usan un protocolo de configuración propietario que no proporciona controles de seguridad de confidencialidad, integridad y autenticidad. Toda la información se envía en texto plano, y puede ser interceptada y modificada. Cualquier comando (incluido el reinicio del dispositivo, la descarga de la configuración o la carga, o la actualización del firmware) es aceptado y ejecutado por el dispositivo sin autenticación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-24 CVE Reserved
- 2019-07-03 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/klsecservices/Advisories/blob/master/KL-MOXA-2018-104.md | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moxa Search vendor "Moxa" | Oncell G3150-hspa Firmware Search vendor "Moxa" for product "Oncell G3150-hspa Firmware" | <= 1.6 Search vendor "Moxa" for product "Oncell G3150-hspa Firmware" and version " <= 1.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3150-hspa Search vendor "Moxa" for product "Oncell G3150-hspa" | - | - |
Safe
|
Moxa Search vendor "Moxa" | Oncell G3150-hspa-t Firmware Search vendor "Moxa" for product "Oncell G3150-hspa-t Firmware" | <= 1.6 Search vendor "Moxa" for product "Oncell G3150-hspa-t Firmware" and version " <= 1.6" | - |
Affected
| in | Moxa Search vendor "Moxa" | Oncell G3150-hspa-t Search vendor "Moxa" for product "Oncell G3150-hspa-t" | - | - |
Safe
|