6.8
CVSSv2

CVE-2017-7917

Published: 29/05/2017 Updated: 09/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Cross-Site Request Forgery issue exists in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an malicious user to modify the configuration of the device.

Vulnerable Product Search on Vulmon Subscribe to Product

moxa oncell_g3110-hspa_firmware

moxa oncell_g3110-hsdpa_firmware

moxa oncell_g3150-hsdpa_firmware

moxa oncell_5104-hsdpa_firmware

moxa oncell_5104-hspa_firmware

moxa oncell_5004-hspa_firmware