PT-2023-8290 · Moxa · Oncell G3150A-Lte Series

CVE-2023-6094

·

Publicado

2023-12-29

·

Atualizado

2024-01-09

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OnCell G3150A-LTE Series firmware versions prior to v1.3
Description The issue is related to the transmission of data in an open manner, which could allow a remote attacker to obtain sensitive information. This could be achieved through eavesdropping on the traffic between the web browser and server, potentially facilitating a subsequent attack against the target.
Recommendations For OnCell G3150A-LTE Series firmware versions prior to v1.3, update to a version that includes the necessary security patches to protect sensitive information during transmission. As a temporary workaround, consider implementing additional encryption methods to protect data in transit until a patched version is available. Restrict access to sensitive information and monitor network traffic for any signs of unauthorized access.

Correção

Cleartext Transmission of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-00373
CVE-2023-6094

Produtos afetados

Oncell G3150A-Lte Series