Moxa Oncell G3470A-Lte-Us-T Firmware vulnerabilities

6 known vulnerabilities affecting moxa/oncell_g3470a-lte-us-t_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4

Vulnerabilities

Page 1 of 1
CVE-2024-4641CRITICALCVSS 9.8≤ 1.7.72024-06-25
CVE-2024-4641 [MEDIUM] CWE-134 CVE-2024-4641: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due t OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
nvd
CVE-2024-4640HIGHCVSS 8.2≤ 1.7.72024-06-25
CVE-2024-4640 [HIGH] CWE-120 CVE-2024-4640: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due t OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash.
nvd
CVE-2024-4639HIGHCVSS 8.8≤ 1.7.72024-06-25
CVE-2024-4639 [HIGH] CWE-77 CVE-2024-4639: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due t OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
nvd
CVE-2024-4638HIGHCVSS 8.8≤ 1.7.72024-06-25
CVE-2024-4638 [HIGH] CWE-77 CVE-2024-4638: OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due t OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
nvd
CVE-2018-11425CRITICALCVSS 9.8≤ 1.62019-07-03
CVE-2018-11425 [CRITICAL] CVE-2018-11425: Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 a Memory corruption issue was discovered in Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11424.
nvd
CVE-2018-11424HIGHCVSS 7.5≤ 1.62019-07-03
CVE-2018-11424 [HIGH] CWE-787 CVE-2018-11424: There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 1 There is Memory corruption in the web interface of Moxa OnCell G3470A-LTE Series version 1.6 Build 18021314 and prior, a different vulnerability than CVE-2018-11425.
nvd