CVE-2018-5453
05.03.2018, 17:29
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.Enginsight
Vendor | Product | Version |
---|---|---|
moxa | oncell_g3110-hspa_firmware | 𝑥 ≤ 1.4 |
moxa | oncell_g3110-hspa-t_firmware | 𝑥 ≤ 1.4 |
moxa | oncell_g3150-hspa_firmware | 𝑥 ≤ 1.4 |
moxa | oncell_g3150-hspa-t_firmware | 𝑥 ≤ 1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-130 - Improper Handling of Length Parameter InconsistencyThe software parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.