CVE-2017-7917
published 2017-05-29CVE-2017-7917: A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.49%
39.0th percentile
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | oncell_5004-hspa_firmware | <= - | — |
| moxa | oncell_5104-hsdpa_firmware | <= - | — |
| moxa | oncell_5104-hspa_firmware | <= - | — |
| moxa | oncell_g3110-hsdpa_firmware | <= 1.2 | — |
| moxa | oncell_g3110-hspa_firmware | <= 1.3 | — |
| moxa | oncell_g3150-hsdpa_firmware | <= 1.4 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Moxa OnCell
cisa_ics·2017-05-23
Moxa OnCell
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa OnCell
Last RevisedMay 23, 2017
Alert CodeICSA-17-143-01
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Moxa
Equipment: OnCell
Vulnerabilities: Improper Restriction of Excessive Authentication Attempts, Plaintext Storage of a Password, and Cross-Site Request Forgery
## AFFECTED PRODUCTS
The following versions of OnCell, a high-speed industrial-grade IP gateway, are affected:
- OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions,
- OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions,
- OnCell G3150-HS
GHSA
GHSA-vvph-6444-j9pj: A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1
ghsa_unreviewed·2022-05-13
CVE-2017-7917 [HIGH] CWE-352 GHSA-vvph-6444-j9pj: A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-05-29
Published