CVE-2017-7917
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
29/05/2017
Last modified:
20/04/2025
Description
A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:moxa:oncell_g3110-hspa_firmware:*:*:*:*:*:*:*:* | 1.3 (including) | |
cpe:2.3:h:moxa:oncell_g3110-hspa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moxa:oncell_g3110-hsdpa_firmware:*:*:*:*:*:*:*:* | 1.2 (including) | |
cpe:2.3:h:moxa:oncell_g3110-hsdpa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moxa:oncell_g3150-hsdpa_firmware:*:*:*:*:*:*:*:* | 1.4 (including) | |
cpe:2.3:h:moxa:oncell_g3150-hsdpa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moxa:oncell_5104-hsdpa_firmware:*:*:*:*:*:*:*:* | - (including) | |
cpe:2.3:h:moxa:oncell_5104-hsdpa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moxa:oncell_5104-hspa_firmware:*:*:*:*:*:*:*:* | - (including) | |
cpe:2.3:h:moxa:oncell_5104-hspa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:moxa:oncell_5004-hspa_firmware:*:*:*:*:*:*:*:* | - (including) | |
cpe:2.3:h:moxa:oncell_5004-hspa:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page