CVE-2018-11427: CSRF
Published Jul 3, 2019
·Updated
CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.
Affected Software
4 affected components
MOXA Oncell G3150-hspa Firmware<=1.4
MOXA Oncell G3150-hspa
MOXA Oncell G3150-hspa-t Firmware<=1.4
MOXA Oncell G3150-hspa-t
Event History
Jul 3, 2019
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11427?
CVE-2018-11427 is classified as a medium severity vulnerability due to the potential for CSRF attacks on device administrators.
2
How do I fix CVE-2018-11427?
To fix CVE-2018-11427, upgrade the Moxa OnCell G3100-HSPA Series firmware to version 1.4 Build 16062920 or later.
3
What are the potential impacts of CVE-2018-11427?
The exploitation of CVE-2018-11427 can allow unauthorized users to perform actions on behalf of the device administrator.
4
Which devices are affected by CVE-2018-11427?
CVE-2018-11427 affects Moxa OnCell G3150-HSPA and G3150-HSPA-T firmware versions 1.4 and earlier.
5
Are there workarounds for CVE-2018-11427?
There are no documented workarounds for CVE-2018-11427 other than applying the firmware update.