CVE Feed

    Dashboard / CVE / CVE-2017-7917

    CVE-2017-7917

    A Cross-Site Request Forgery issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1.4 Build 11051315 and previous versions, OnCell 5104-HSDPA, OnCell 5104-HSPA, and OnCell 5004-HSPA. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request, which could allow an attacker to modify the configuration of the device.

    Published:May 29, 2017
    Last Modified:Apr 20, 2025
    EPS:May 29, 2017
    EPSS Score:0.00103
    CVSS Score:8.8

    Affected Products

    Vendor
    Moxa
    Product
    Oncell 5004-hspa
    Vendor
    Moxa
    Product
    Oncell 5004-hspa Firmware
    Vendor
    Moxa
    Product
    Oncell 5104-hsdpa
    Vendor
    Moxa
    Product
    Oncell 5104-hsdpa Firmware
    Vendor
    Moxa
    Product
    Oncell 5104-hspa
    Vendor
    Moxa
    Product
    Oncell 5104-hspa Firmware
    Vendor
    Moxa
    Product
    Oncell G3110-hsdpa
    Vendor
    Moxa
    Product
    Oncell G3110-hsdpa Firmware
    Vendor
    Moxa
    Product
    Oncell G3110-hspa
    Vendor
    Moxa
    Product
    Oncell G3110-hspa Firmware
    Vendor
    Moxa
    Product
    Oncell G3150-hsdpa
    Vendor
    Moxa
    Product
    Oncell G3150-hsdpa Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High