First published: Tue Jun 25 2024(Updated: )
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Credit: psirt@moxa.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Moxa Oncell G3470A-LTE-US-T | <=1.7.7 | |
Moxa OnCell G3470A-LTE-US-T | ||
All of | ||
Moxa Oncell G3470A-LTE Firmware | <=1.7.7 | |
Moxa Oncell G3470A-LTE-EU | ||
All of | ||
Moxa Oncell G3470A-LTE-EU-T Firmware | <=1.7.7 | |
Moxa Oncell G3470A-LTE-EU-T Firmware | ||
All of | ||
Moxa Oncell G3470A-LTE-US-T | <=1.7.7 | |
Moxa Oncell G3470A-LTE-US Firmware |
Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * OnCell G3470A-LTE Series: Please contact Moxa Technical Support for the security patch (v1.7.8). https://www.moxa.com/tw/support/technical-support
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4639 has not been assigned a specific severity score, but it could potentially allow unauthorized execution of commands.
To mitigate CVE-2024-4639, it is recommended to upgrade the OnCell G3470A-LTE Series firmware to a version later than v1.7.7.
Moxa OnCell G3470A-LTE firmware versions v1.7.7 and prior are affected by CVE-2024-4639.
CVE-2024-4639 is a command injection vulnerability related to the IPSec configuration.
Yes, an attacker can exploit CVE-2024-4639 remotely due to the nature of the vulnerability.