Description
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16888 | A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device. |
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-17-143-01 |
|
History
No history.
Subscriptions
Moxa
Subscribe
Oncell 5004-hspa
Subscribe
Oncell 5004-hspa Firmware
Subscribe
Oncell 5104-hsdpa
Subscribe
Oncell 5104-hsdpa Firmware
Subscribe
Oncell 5104-hspa
Subscribe
Oncell 5104-hspa Firmware
Subscribe
Oncell G3110-hsdpa
Subscribe
Oncell G3110-hsdpa Firmware
Subscribe
Oncell G3110-hspa
Subscribe
Oncell G3110-hspa Firmware
Subscribe
Oncell G3150-hsdpa
Subscribe
Oncell G3150-hsdpa Firmware
Subscribe
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T16:19:29.287Z
Reserved: 2017-04-18T00:00:00.000Z
Link: CVE-2017-7917
No data.
Status : Modified
Published: 2017-05-29T16:29:00.240
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7917
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD