PT-2023-8290 · Moxa · Oncell G3150A-Lte Series
Published
2023-12-29
·
Updated
2024-01-09
·
CVE-2023-6094
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OnCell G3150A-LTE Series firmware versions prior to v1.3
Description
The issue is related to the transmission of data in an open manner, which could allow a remote attacker to obtain sensitive information. This could be achieved through eavesdropping on the traffic between the web browser and server, potentially facilitating a subsequent attack against the target.
Recommendations
For OnCell G3150A-LTE Series firmware versions prior to v1.3, update to a version that includes the necessary security patches to protect sensitive information during transmission. As a temporary workaround, consider implementing additional encryption methods to protect data in transit until a patched version is available. Restrict access to sensitive information and monitor network traffic for any signs of unauthorized access.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oncell G3150A-Lte Series