First published: Mon Mar 05 2018(Updated: )
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Oncell G3110-HSDPA Firmware | <=1.4 | |
Moxa Oncell G3110-HSPA Firmware | ||
Moxa Oncell G3110-HSDPA Firmware | <=1.4 | |
Moxa Oncell G3110-HSDPA Firmware | ||
Moxa Oncell G3150-HSDPA Firmware | <=1.4 | |
Moxa Oncell G3150-HSPA-T Firmware | ||
Moxa OnCell G3150-HSPA-T Firmware | <=1.4 | |
Moxa Oncell G3150-HSPA-T Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5453 is considered a medium severity vulnerability due to its potential to make the affected devices unavailable.
To fix CVE-2018-5453, upgrade to a version later than 1.4 for Moxa OnCell G3100-HSPA and G3150-HSPA series firmware.
CVE-2018-5453 affects Moxa OnCell G3100-HSPA and G3150-HSPA series devices running firmware version 1.4 and prior.
CVE-2018-5453 facilitates an attack that may exploit HTTP request manipulation leading to device unavailability.
Yes, there is an official advisory from ICS-CERT detailing CVE-2018-5453 and its mitigation.