CVE-2016-8363
published 2017-02-13CVE-2016-8363: An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2…
PriorityP260critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
1.85%
76.6th percentile
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. User is able to execute arbitrary OS commands on the server.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | awk-1121_firmware | <= 06-29-2017 | — |
| moxa | awk-1127_firmware | <= 06-29-2017 | — |
| moxa | awk-1131a_firmware | <= 10-31-2016 | — |
| moxa | awk-3121-m12-rtg_firmware | <= 06-29-2017 | — |
| moxa | awk-3131-m12-rcc_firmware | <= 06-29-2017 | — |
| moxa | awk-3131a_firmware | <= 10-31-2016 | — |
| moxa | awk-3191_firmware | <= 05-30-2017 | — |
| moxa | awk-4131a_firmware | <= 10-31-2016 | — |
| moxa | awk-5232-m12-rcc_firmware | <= 06-29-2017 | — |
| moxa | awk-5232_firmware | <= 05-30-2017 | — |
| moxa | awk-6232_firmware | <= 05-30-2017 | — |
| moxa | oncellg3470a-lte_firmware | <= 10-31-2016 | — |
| moxa | wac-1001_v2_firmware | <= 06-29-2017 | — |
| moxa | wac-2004_firmware | <= 06-29-2017 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Arbitrary OS command execution is possible via the web console by an unauthenticated user on affected Moxa OnCell/AWK/WAC/TAP devices — monitor for unexpected OS command execution originating from the web management interface process. ↗
- →The vulnerability is exploitable remotely with no user interaction required; network-level detection should alert on unexpected inbound connections to the HTTP/HTTPS administrative web management interface of affected Moxa devices from untrusted sources. ↗
- →An attacker with low skill can exploit this vulnerability; treat any anomalous authenticated (high-privilege) HTTP/HTTPS session to the device management interface as suspicious, particularly sessions issuing system-level commands. ↗
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gh4q-35j7-558p: An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WA
ghsa_unreviewed·2022-05-17
CVE-2016-8363 [CRITICAL] GHSA-gh4q-35j7-558p: An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WA
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-5232-M12-RCC Series, TAP-6226 Series, AWK-3121/4121 Series, AWK-3131/4131 Series, and AWK-5222/6222 Series. User is able to execute arbitrary OS commands on the server.
CISA ICS
Moxa OnCell Security Vulnerabilities
cisa_ics·2019-10-23
Moxa OnCell Security Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa OnCell Security Vulnerabilities
Last RevisedOctober 23, 2019
Alert CodeICSA-16-308-01
## OVERVIEW
Independent researcher Maxim Rupp has identified authorization bypass and disclosed OS commanding vulnerabilities in Moxa’s OnCell Security Software. Moxa has produced a new version to mitigate these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following Moxa OnCell versions are affected:
- OnCellG3470A-LTE,
- AWK-1131A/3131A/4131A Series,
- AWK-3191 Series,
- AWK-5232/6232 Series,
- AWK-1121/1127 Series,
- WAC-1001 V2 Se
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-02-13
Published