CVE-2024-4641

OnCell G3470A-LTE Series: Authenticated Format String Errors

Description

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.

Remediation

Solution:

  • Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * OnCell G3470A-LTE Series: Please contact Moxa Technical Support for the security patch (v1.7.8). https://www.moxa.com/tw/support/technical-support

Workaround:

  • Moxa recommends users to implement the following mitigations if necessary: * Minimize network exposure to ensure the device is not accessible from the Internet. * When remote access is required, use secure methods, such as Virtual Private Networks (VPNs). * The starting point of all the above vulnerabilities is from the web service, so it is suggested to disable web service temporarily if you completed configuration to prevent further damages from these vulnerabilities until installed patch or updated firmware.

Category

6.3
CVSS
Severity: Medium
CVSS 3.1 •
EPSS 0.30%
Vendor Advisory moxa.com
Affected: Moxa OnCell G3150A-LTE Series
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2024-4641?
CVE-2024-4641 has been scored as a medium severity vulnerability.
How to fix CVE-2024-4641?
To fix CVE-2024-4641: Moxa has developed appropriate solutions to address the vulnerabilities. The solutions for affected products are shown below. * OnCell G3470A-LTE Series: Please contact Moxa Technical Support for the security patch (v1.7.8). https://www.moxa.com/tw/support/technical-support
Is CVE-2024-4641 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2024-4641 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2024-4641?
CVE-2024-4641 affects Moxa OnCell G3150A-LTE Series.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.