PT-2023-8290 · Moxa · Oncell G3150A-Lte Series

CVE-2023-6094

·

Published

2023-12-29

·

Updated

2024-01-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OnCell G3150A-LTE Series firmware versions prior to v1.3
Description The issue is related to the transmission of data in an open manner, which could allow a remote attacker to obtain sensitive information. This could be achieved through eavesdropping on the traffic between the web browser and server, potentially facilitating a subsequent attack against the target.
Recommendations For OnCell G3150A-LTE Series firmware versions prior to v1.3, update to a version that includes the necessary security patches to protect sensitive information during transmission. As a temporary workaround, consider implementing additional encryption methods to protect data in transit until a patched version is available. Restrict access to sensitive information and monitor network traffic for any signs of unauthorized access.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00373
CVE-2023-6094

Affected Products

Oncell G3150A-Lte Series