PT-2015-3219 · Moxa · Moxa Oncell Central Manager

Andrea Micalizzi

·

Published

2015-09-29

·

Updated

2015-12-21

·

CVE-2015-6480

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moxa OnCell Central Manager versions prior to 2.2
Description The issue is related to the MessageBrokerServlet servlet, which does not require authentication. This allows remote attackers to obtain administrative access via a command. For example, the addUserAndGroup action can be exploited to gain administrative privileges. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the MessageBrokerServlet servlet to minimize the risk of exploitation. Avoid using the addUserAndGroup action in the affected servlet until the issue is resolved.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00965
CVE-2015-6480
ZDI-15-452

Affected Products

Moxa Oncell Central Manager