// For flags

CVE-2018-5455

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.

Se ha descubierto un problema de dependencia en cookies sin comprobación de validación e integridad en Moxa OnCell G3100-HSPA Series en versiones 1.4 Build 16062919 y anteriores. La aplicación permite que un parámetro de la cookie consista solo de dígitos, lo que permite que un atacante realice un ataque de fuerza bruta que omita la autenticación y obtenga acceso a las funciones del dispositivo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-12 CVE Reserved
  • 2018-03-05 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
  • CWE-565: Reliance on Cookies without Validation and Integrity Checking
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Moxa
Search vendor "Moxa"
Oncell G3110-hspa Firmware
Search vendor "Moxa" for product "Oncell G3110-hspa Firmware"
<= 1.4
Search vendor "Moxa" for product "Oncell G3110-hspa Firmware" and version " <= 1.4"
-
Affected
in Moxa
Search vendor "Moxa"
Oncell G3110-hspa
Search vendor "Moxa" for product "Oncell G3110-hspa"
--
Safe
Moxa
Search vendor "Moxa"
Oncell G3110-hspa-t Firmware
Search vendor "Moxa" for product "Oncell G3110-hspa-t Firmware"
<= 1.4
Search vendor "Moxa" for product "Oncell G3110-hspa-t Firmware" and version " <= 1.4"
-
Affected
in Moxa
Search vendor "Moxa"
Oncell G3110-hspa-t
Search vendor "Moxa" for product "Oncell G3110-hspa-t"
--
Safe
Moxa
Search vendor "Moxa"
Oncell G3150-hspa Firmware
Search vendor "Moxa" for product "Oncell G3150-hspa Firmware"
<= 1.4
Search vendor "Moxa" for product "Oncell G3150-hspa Firmware" and version " <= 1.4"
-
Affected
in Moxa
Search vendor "Moxa"
Oncell G3150-hspa
Search vendor "Moxa" for product "Oncell G3150-hspa"
--
Safe
Moxa
Search vendor "Moxa"
Oncell G3150-hspa-t Firmware
Search vendor "Moxa" for product "Oncell G3150-hspa-t Firmware"
<= 1.4
Search vendor "Moxa" for product "Oncell G3150-hspa-t Firmware" and version " <= 1.4"
-
Affected
in Moxa
Search vendor "Moxa"
Oncell G3150-hspa-t
Search vendor "Moxa" for product "Oncell G3150-hspa-t"
--
Safe