Product support

Security Advisories

SUMMARY

OnCell Central Manager Cellular Management Software Vulnerabilities

  • Version: V1.0
  • Release Date: Mar 16, 2020
  • Reference:
    • CVE-2017-5641, CVE-2015-3269

Multiple product vulnerabilities were identified in Moxa’s cellular management software OnCell Central Manager. The vulnerabilities are based on Apache Flex BlazeDS’s, a third-party component, that is embedded on the OnCell central manager. In response to this, Moxa has developed related solutions to address the vulnerabilities.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1 Deserialization of Untrusted Data (CWE-502), CVE-2017-5641 Remote code execution on third-party component: Apache Flex BlazeDS
2 Information Exposure (CWE-200), CVE-2015-3269 XML External Entity (XXE) processing on third-party component: Apache Flex BlazeDS
AFFECTED PRODUCTS AND SOLUTIONS

Affected Products:

The affected products and firmware versions are shown below.

Product Series Affected Versions
OnCell Central Manager Version lower than 2.4.1

 

Solutions:

Moxa has developed appropriate solutions to address the vulnerability. The solutions for affected products are shown below.

Product Series Affected Versions
OnCell Central Manager The library that uses OnCell Central Manager has been migrated to Apache's latest release version 4.7.3 which has fixed these vulnerabilities.
Please contact Moxa Technical Support for the security patch.

 

Acknowledgment:

We would like to express our appreciation to Sergey Temnikov from Kaspersky ICS CERT for reporting the vulnerability, working with us to help enhance the security of our products, and helping us provide a better service to our customers.

 

Revision History:

VERSION DESCRIPTION RELEASE DATE
1.0 First Release Mar 16, 2020

Relevant Products

OnCell Central Manager ·

  •   Print this page
  • You can manage and share your saved list in My Moxa
Let’s get that fixed

If you are concerned about a potential cybersecurity vulnerability, please contact us and one of technical support staff will get in touch with you.

Report a Vulnerability
Added To Bag