First published: Mon Mar 05 2018(Updated: )
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Moxa Oncell G3110-hspa Firmware | <=1.4 | |
Moxa OnCell G3110-HSPA | ||
Moxa Oncell G3110-hspa-t Firmware | <=1.4 | |
Moxa Oncell G3110-hspa-t | ||
Moxa Oncell G3150-hspa Firmware | <=1.4 | |
Moxa Oncell G3150-hspa | ||
Moxa Oncell G3150-hspa-t Firmware | <=1.4 | |
Moxa Oncell G3150-hspa-t |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.