CVE-2024-4641

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
MoxaCNA
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
moxaoncell_g3470a-lte-us-t_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-eu_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-eu-t_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-us_firmware
𝑥
≤ 1.7.7
𝑥
= Vulnerable software versions