PT-2023-8290 · Moxa · Oncell G3150A-Lte Series
CVE-2023-6094
·
Publicado
2023-12-29
·
Atualizado
2024-01-09
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OnCell G3150A-LTE Series firmware versions prior to v1.3
Description
The issue is related to the transmission of data in an open manner, which could allow a remote attacker to obtain sensitive information. This could be achieved through eavesdropping on the traffic between the web browser and server, potentially facilitating a subsequent attack against the target.
Recommendations
For OnCell G3150A-LTE Series firmware versions prior to v1.3, update to a version that includes the necessary security patches to protect sensitive information during transmission. As a temporary workaround, consider implementing additional encryption methods to protect data in transit until a patched version is available. Restrict access to sensitive information and monitor network traffic for any signs of unauthorized access.
Correção
Cleartext Transmission of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oncell G3150A-Lte Series