Description

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.

INFO

Published Date :

2024-06-25T08:49:24.910Z

Last Modified :

2024-08-01T20:47:41.421Z

Source :

Moxa
AFFECTED PRODUCTS

The following products are affected by CVE-2024-4638 vulnerability.

Vendors Products
Moxa
  • Oncell G3470a-lte-eu
  • Oncell G3470a-lte-eu-t
  • Oncell G3470a-lte-eu-t Firmware
  • Oncell G3470a-lte-eu Firmware
  • Oncell G3470a-lte-us
  • Oncell G3470a-lte-us-t
  • Oncell G3470a-lte-us-t Firmware
  • Oncell G3470a-lte-us Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-4638.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact