CVE-2018-5455: Critical severity MOXA Oncell G3110-hspa Firmware vulnerability
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Moxa OnCell G3100-HSPA Seriesto a version that resolves this vulnerability.Fixed in 1.4 Build 16062919
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5455?
CVE-2018-5455 has been classified as a high severity vulnerability due to its potential to allow unauthorized access through brute force attacks.
How do I fix CVE-2018-5455?
To fix CVE-2018-5455, update the Moxa OnCell G3100-HSPA Series firmware to a version later than 1.4 Build 16062919.
What impact does CVE-2018-5455 have on affected devices?
CVE-2018-5455 allows attackers to bypass authentication, compromising the security of affected Moxa OnCell devices.
Which Moxa devices are affected by CVE-2018-5455?
CVE-2018-5455 affects the Moxa OnCell G3100-HSPA Series, including the G3110 and G3150 models with firmware version 1.4 and earlier.
Is there a workaround for CVE-2018-5455 until a patch is applied?
Currently, there are no known workarounds for CVE-2018-5455, so it is essential to update the firmware to mitigate the risk.