CVE-2018-5453
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
Affected (4)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3110 Hspa | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3110 Hspa T | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3150 Hspa | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Oncell G3150 Hspa T | All versions |
Related CWEs
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-130
Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
References (2)
Source: ics-cert@hq.dhs.gov
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Timeline
No history available yet.