PT-2021-7482 · Moxa · Moxa Oncell G3470A-Lte+6
Published
2021-12-30
·
Updated
2021-12-30
·
CVE-2021-37753
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Moxa OnCell G3150A-LTE versions (affected versions not specified)
Moxa OnCell G3470A-LTE versions (affected versions not specified)
Moxa WDR-3124A versions (affected versions not specified)
Moxa AWK-3131A versions (affected versions not specified)
Moxa AWK-4131A versions (affected versions not specified)
Moxa AWK-1131A versions (affected versions not specified)
Moxa AWK-1137C versions (affected versions not specified)
Description
The issue is related to the storage of critical information without encryption in the firmware of certain Moxa industrial LTE modems and wireless access points. This could allow a remote attacker to bypass security restrictions and gain unauthorized access to protected information.
Recommendations
For Moxa OnCell G3150A-LTE, consider disabling remote access until a patch is available.
For Moxa OnCell G3470A-LTE, restrict access to sensitive information to minimize the risk of exploitation.
For Moxa WDR-3124A, avoid using the device for critical operations until the issue is resolved.
For Moxa AWK-3131A, AWK-4131A, AWK-1131A, and AWK-1137C, limit the use of wireless access points to necessary operations only.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Awk-1131A
Moxa Awk-1137C
Moxa Awk-3131A
Moxa Awk-4131A
Moxa Oncell G3150A-Lte
Moxa Oncell G3470A-Lte
Moxa Wdr-3124A