A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-17225 A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application allows a cookie parameter to consist of only digits, allowing an attacker to perform a brute force attack bypassing authentication and gaining access to device functions.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T05:33:44.372Z

Reserved: 2018-01-12T00:00:00

Link: CVE-2018-5455

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-05T17:29:00.613

Modified: 2024-11-21T04:08:50.163

Link: CVE-2018-5455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses