CVE-2023-6094 Vulnerability Details

  /     /     /  

CVE-2023-6094 Metadata Quick Info

CVE Published: 31/12/2023 | CVE Updated: 26/08/2024 | CVE Year: 2023
Source: Moxa | Vendor: Moxa | Product: OnCell G3150A-LTE Series
Status : PUBLISHED

CVE-2023-6094 Description

A vulnerability has been identified in OnCell G3150A-LTE Series firmware versions v1.3 and prior. The vulnerability results from lack of protection for sensitive information during transmission. An attacker eavesdropping on the traffic between the web browser and server may obtain sensitive information. This type of attack could be executed to gather sensitive information or to facilitate a subsequent attack against the target.

Metrics

CVSS Version: 3.1 | Base Score: 5.3 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-319
CWE Name: CWE-319: Cleartext Transmission of Sensitive Information
Source: Moxa

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-117
CAPEC Description: CAPEC-117: Interception


Source: NVD (National Vulnerability Database).