CVE-2018-11421: Critical severity moxa oncell g3150-hsdpa firmware vulnerability
Moxa OnCell G3100-HSPA Series version 1.6 Build 17100315 and prior use a proprietary monitoring protocol that does not provide confidentiality, integrity, and authenticity security controls. All information is sent in plain text, and can be intercepted and modified. The protocol is vulnerable to remote unauthenticated disclosure of sensitive information, including the administrator's password. Under certain conditions, it's also possible to retrieve additional information, such as content of HTTP requests to the device, or the previously used password, due to memory leakages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11421?
The severity of CVE-2018-11421 is classified as high due to the lack of security controls in the monitoring protocol.
How do I fix CVE-2018-11421?
To fix CVE-2018-11421, update the firmware of Moxa OnCell G3100-HSPA Series devices to a version later than 1.6 Build 17100315.
What are the risks associated with CVE-2018-11421?
The risks associated with CVE-2018-11421 include interception and modification of sensitive information transmitted in plain text.
Which devices are affected by CVE-2018-11421?
CVE-2018-11421 affects the Moxa OnCell G3100-HSPA Series devices running firmware version 1.6 or earlier.
Is it safe to use Moxa OnCell G3100-HSPA devices with CVE-2018-11421?
It is not safe to use Moxa OnCell G3100-HSPA devices with CVE-2018-11421 due to their vulnerability to data interception and manipulation.