8.8
CVE-2024-4639
- EPSS 1.55%
- Veröffentlicht 25.06.2024 10:15:19
- Zuletzt bearbeitet 10.03.2025 20:07:31
- Quelle psirt@moxa.com
- CVE-Watchlists
- Unerledigt
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Moxa ≫ Oncell G3470a-lte-us-t Firmware Version <= 1.7.7
Moxa ≫ Oncell G3470a-lte-eu Firmware Version <= 1.7.7
Moxa ≫ Oncell G3470a-lte-eu-t Firmware Version <= 1.7.7
Moxa ≫ Oncell G3470a-lte-us Firmware Version <= 1.7.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.55% | 0.809 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| psirt@moxa.com | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.