security updates for Moxa OnCell

Number: AV16-133
Date: 25 August 2016

Purpose

The purpose of this advisory is to bring attention to the following security updates for Moxa OnCell.

Assessment

Moxa has issued a firmware update to their OnCell products that fix multiple security vulnerabilities. One of those vulnerabilities could allow an attacker to use brute force attack against authentication system.

Versions Affected:
OnCell G3100V2 Series, prior to version 2.8
OnCell G3111/G3151/G3211/G3251 Series, prior to version 1.7

CVE Reference: CVE-2016-5799, CVE-2016-5812

Suggested Action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.  For more information, please refer to the ICS-CERT reference.

References:

https://ics-cert.us-cert.gov/advisories/ICSA-16-236-01

Date modified: