CVE-2018-5453: Buffer Overflow
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Moxa OnCell G3100-HSPA Seriesto a version that resolves this vulnerability.Fixed in 1.4 Build 16062919
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5453?
CVE-2018-5453 is considered a medium severity vulnerability due to its potential to make the affected devices unavailable.
How do I fix CVE-2018-5453?
To fix CVE-2018-5453, upgrade to a version later than 1.4 for Moxa OnCell G3100-HSPA and G3150-HSPA series firmware.
What devices are affected by CVE-2018-5453?
CVE-2018-5453 affects Moxa OnCell G3100-HSPA and G3150-HSPA series devices running firmware version 1.4 and prior.
What type of attack does CVE-2018-5453 facilitate?
CVE-2018-5453 facilitates an attack that may exploit HTTP request manipulation leading to device unavailability.
Is there an official advisory for CVE-2018-5453?
Yes, there is an official advisory from ICS-CERT detailing CVE-2018-5453 and its mitigation.