// For flags

CVE-2023-6094

OnCell G3150A-LTE Series: Web Server Transmits Cleartext Credentials

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of attack could be executed to gather sensitive information or to facilitate a subsequent attack against the target.

Se ha identificado una vulnerabilidad en las versiones de firmware de la serie OnCell G3150A-LTE v1.3 y anteriores. La vulnerabilidad se debe a la falta de protección de la información confidencial durante la transmisión. Un atacante que escuche el tráfico entre el navegador web y el servidor puede obtener información confidencial. Este tipo de ataque podría ejecutarse para recopilar información confidencial o para facilitar un ataque posterior contra el objetivo.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-11-13 CVE Reserved
  • 2023-12-31 CVE Published
  • 2024-01-10 EPSS Updated
  • 2024-08-26 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
  • CAPEC-117: Interception
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Moxa
Search vendor "Moxa"
Oncell G3150a-lte Firmware
Search vendor "Moxa" for product "Oncell G3150a-lte Firmware"
<= 1.3
Search vendor "Moxa" for product "Oncell G3150a-lte Firmware" and version " <= 1.3"
-
Affected
in Moxa
Search vendor "Moxa"
Oncell G3150a-lte
Search vendor "Moxa" for product "Oncell G3150a-lte"
--
Safe