CVE-2024-4641: OnCell G3470A-LTE Series: Authenticated Format String Errors
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OnCell G3470A-LTE Series firmwareto a version that resolves this vulnerability.Fixed in v1.7.8Patch security patch - Compensating control
For OnCell G3470A-LTE Series devices running firmware v1.7.7 and prior, contact Moxa Technical Support for the security patch to address the issue where the device accepts a format string from an external source as an argument.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4641?
CVE-2024-4641 is classified as a high severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2024-4641?
To fix CVE-2024-4641, update the firmware of the OnCell G3470A-LTE series to version v1.7.8 or later.
What types of attacks can exploit CVE-2024-4641?
CVE-2024-4641 can be exploited through remote format string attacks resulting in memory leaks and denial of service.
Which firmware versions are affected by CVE-2024-4641?
CVE-2024-4641 affects all firmware versions v1.7.7 and prior of the OnCell G3470A-LTE series.
What devices are impacted by CVE-2024-4641?
Devices impacted by CVE-2024-4641 include the Moxa OnCell G3470A-LTE-EU, G3470A-LTE-US, and their corresponding variants.