CVE-2024-4640: OnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmail
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OnCell G3470A-LTE Series firmwareto a version that resolves this vulnerability.Fixed in v1.7.8 - Compensating control
If you cannot update immediately, contact Moxa Technical Support to obtain the security patch for OnCell G3470A-LTE Series (v1.7.8).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4640?
CVE-2024-4640 has been classified as a medium severity vulnerability due to the potential for application crashes.
How do I fix CVE-2024-4640?
To fix CVE-2024-4640, upgrade the firmware of the Moxa Oncell G3470A-LTE Series to version 1.7.8 or later.
What products are affected by CVE-2024-4640?
CVE-2024-4640 affects Moxa Oncell G3470A-LTE Series firmware versions 1.7.7 and prior.
What type of vulnerability is CVE-2024-4640?
CVE-2024-4640 is a buffer overflow vulnerability caused by missing bounds checking.
Can CVE-2024-4640 be exploited remotely?
Yes, CVE-2024-4640 can potentially be exploited remotely if an attacker can send crafted requests to the affected devices.