CVE-2023-33239
Published: Aug 17, 2023
Modified: Oct 28, 2024
CVSS v3.1
8.8
Description
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices.
| Vendor | Product | Versions |
|---|---|---|
Moxa | TN-5900 Series | affected 1.0 - <= 3.3 |
Moxa | TN-4900 Series | affected 1.0 - <= 1.2.4 |
Moxa | EDR-810 Series | affected 1.0 - <= 5.12.27 |
Moxa | EDR-G902 Series | affected 1.0 - <= 5.7.17 |
Moxa | EDR-G903 Series | affected 1.0 - <= 5.7.15 |
Moxa | EDR-G9010 Series | affected 1.0 - <= 2.1 |
Moxa | NAT-102 Series | affected 1.0 - <= 1.0.3 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now