← Back to home
ICSA-17-143-01  ·  Published 2017-05-23  ·  View on CISA ICS-CERT ↗

Moxa OnCell

CVSS 9.8 CRITICAL

Risk Summary

ATTENTION: Remotely exploitable/low skill level to exploit.

Remediations

  • For OnCell G31x0-HSPA and OnCell 5x04-HSPA devices users should upgrade to the latest official firmware Version 1.4 or above.
  • For OnCell G31x0-HSDPA and OnCell 5x04-HSDPA devices users should disable HTTP and use other another console such as HTTPS to access web UI or SNMP/Telnet. Moxa reports that the HSDPA devices have been phased out. If further assistance is needed, please contact Moxa.

Affected Vendors

Moxa

Affected Products (3)

Moxa · OnCell G3110-HSDPA <= 1.2 build 09123015
Moxa · OnCell G3150-HSDPA <= 1.4 build 11051315
Moxa · OnCell G3110-HSPA <= 1.3 build 15082117

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more