7.8
CVE-2018-5453
- EPSS 0.23%
- Veröffentlicht 05.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:49
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
An Improper Handling of Length Parameter Inconsistency issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker may be able to edit the element of an HTTP request, causing the device to become unavailable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Oncell G3110-hspa Firmware Version <= 1.4
Moxa ≫ Oncell G3110-hspa-t Firmware Version <= 1.4
Moxa ≫ Oncell G3150-hspa Firmware Version <= 1.4
Moxa ≫ Oncell G3150-hspa-t Firmware Version <= 1.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.429 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-130 Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.