CVE-2018-5453
published 2018-03-05CVE-2018-5453: An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.21%
64.9th percentile
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | oncell_g3110-hspa-t_firmware | <= 1.4 | — |
| moxa | oncell_g3110-hspa_firmware | <= 1.4 | — |
| moxa | oncell_g3150-hspa-t_firmware | <= 1.4 | — |
| moxa | oncell_g3150-hspa_firmware | <= 1.4 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5fj-f6xf-9jxc: An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1
ghsa_unreviewed·2022-05-13
CVE-2018-5453 [HIGH] CWE-119 GHSA-f5fj-f6xf-9jxc: An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
CISA ICS
Moxa OnCell G3100-HSPA Series
cisa_ics·2018-03-01
Moxa OnCell G3100-HSPA Series
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Moxa OnCell G3100-HSPA Series
Last RevisedMarch 01, 2018
Alert CodeICSA-18-060-02
## CVSS v3 9.8
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Moxa
Equipment: OnCell G3100-HSPA Series
Vulnerabilities: Reliance on Cookies without Validation and Integrity Checking, Improper Handling of Length Parameter Inconsistency, NULL Pointer Dereference
## AFFECTED PRODUCTS
The following versions of OnCell, a high-speed industrial-grade IP gateway, are affected:
- OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior.
## IMPACT
Successful exploitation of
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-05
Published