CVE-2024-4641
published 2024-06-25CVE-2024-4641: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.34%
26.3th percentile
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| moxa | oncell_g3150a-lte_series | 1.0 – 1.7.7 | — |
| moxa | oncell_g3470a-lte-eu-t_firmware | <= 1.7.7 | — |
| moxa | oncell_g3470a-lte-eu_firmware | <= 1.7.7 | — |
| moxa | oncell_g3470a-lte-us-t_firmware | <= 1.7.7 | — |
| moxa | oncell_g3470a-lte-us_firmware | <= 1.7.7 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jqr-jfvv-cj9j: OnCell G3470A-LTE Series firmware versions v1
ghsa_unreviewed·2024-06-25
CVE-2024-4641 [MEDIUM] CWE-134 GHSA-9jqr-jfvv-cj9j: OnCell G3470A-LTE Series firmware versions v1
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (shadow-utils) — CVE-2023-4641
vendor_oracle·2024-04-15·CVSS 5.5
CVE-2023-4641 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (shadow-utils) — CVE-2023-4641
Oracle Oracle Communications Risk Matrix: Install/Upgrade (shadow-utils) vulnerability
CVE: CVE-2023-4641
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2024 (APR 2024)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-25
Published