CVE-2024-4641

EUVD-2024-44245
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
MoxaCNA
6.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
moxaoncell_g3470a-lte-us-t_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-eu_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-eu-t_firmware
𝑥
≤ 1.7.7
moxaoncell_g3470a-lte-us_firmware
𝑥
≤ 1.7.7
𝑥
= Vulnerable software versions