PT-2023-8290 · Moxa · Oncell G3150A-Lte Series

Published

2023-12-29

·

Updated

2024-01-09

·

CVE-2023-6094

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OnCell G3150A-LTE Series firmware versions prior to v1.3
Description The issue is related to the transmission of data in an open manner, which could allow a remote attacker to obtain sensitive information. This could be achieved through eavesdropping on the traffic between the web browser and server, potentially facilitating a subsequent attack against the target.
Recommendations For OnCell G3150A-LTE Series firmware versions prior to v1.3, update to a version that includes the necessary security patches to protect sensitive information during transmission. As a temporary workaround, consider implementing additional encryption methods to protect data in transit until a patched version is available. Restrict access to sensitive information and monitor network traffic for any signs of unauthorized access.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-00373
CVE-2023-6094

Affected Products

Oncell G3150A-Lte Series