CVE-2023-33238
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially allow malicious users to execute remote code on affected devices.
Affected (2)
Products: Moxa: Tn 5900 Firmware, Tn 4900 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3 |
| Running on/with | Platform Versions |
|---|---|
Moxa Tn 5900 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.2.4 |
| Running on/with | Platform Versions |
|---|---|
Moxa Tn 4900 | All versions |
Related CWEs
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
References (2)
Source: psirt@moxa.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.