Vulnerability Description
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moxa | Oncell G3470A-Lte-Us-T Firmware | <= 1.7.7 |
| Moxa | Oncell G3470A-Lte-Us-T | - |
| Moxa | Oncell G3470A-Lte-Eu Firmware | <= 1.7.7 |
| Moxa | Oncell G3470A-Lte-Eu | - |
| Moxa | Oncell G3470A-Lte-Eu-T Firmware | <= 1.7.7 |
| Moxa | Oncell G3470A-Lte-Eu-T | - |
| Moxa | Oncell G3470A-Lte-Us Firmware | <= 1.7.7 |
| Moxa | Oncell G3470A-Lte-Us | - |
Related Weaknesses (CWE)
References
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-onVendor Advisory
- https://www.moxa.com/en/support/product-support/security-advisory/mpsa-242550-onVendor Advisory
FAQ
What is CVE-2024-4641?
CVE-2024-4641 is a vulnerability with a CVSS score of 6.3 (MEDIUM). OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an exte...
How severe is CVE-2024-4641?
CVE-2024-4641 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-4641?
Check the references section above for vendor advisories and patch information. Affected products include: Moxa Oncell G3470A-Lte-Us-T Firmware, Moxa Oncell G3470A-Lte-Us-T, Moxa Oncell G3470A-Lte-Eu Firmware, Moxa Oncell G3470A-Lte-Eu, Moxa Oncell G3470A-Lte-Eu-T Firmware.