Description
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-17225 | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions. |
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-18-060-02 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T05:33:44.372Z
Reserved: 2018-01-12T00:00:00.000Z
Link: CVE-2018-5455
No data.
Status : Modified
Published: 2018-03-05T17:29:00.613
Modified: 2024-11-21T04:08:50.163
Link: CVE-2018-5455
No data.
OpenCVE Enrichment
No data.
EUVD