CVE-2023-6093 Vulnerability Details

  /     /     /  

CVE-2023-6093 Metadata Quick Info

CVE Published: 31/12/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: Moxa | Vendor: Moxa | Product: OnCell G3150A-LTE Series
Status : PUBLISHED

CVE-2023-6093 Description

A clickjacking vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. This vulnerability is caused by incorrectly restricts frame objects, which can lead to user confusion about which interface the user is interacting with. This vulnerability may lead the attacker to trick the user into interacting with the application.

Metrics

CVSS Version: 3.1 | Base Score: 5.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* HIGH
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-1021
CWE Name: CWE-1021: Improper Restriction of Rendered UI Layers or Frames
Source: Moxa

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-103
CAPEC Description: CAPEC-103: Clickjacking


Source: NVD (National Vulnerability Database).