PT-2023-4621 · Unknown · Tn-5900 Series

CVE-2023-34213

·

Publicado

2023-08-16

·

Atualizado

2024-10-28

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TN-5900 Series firmware versions v3.3 and prior
Description The issue stems from insufficient input validation and improper authentication in the key-generation function. This could potentially allow malicious users to execute remote code on affected devices. The vulnerability is related to errors in processing input data in the key-generation function, which may enable a remote attacker to execute arbitrary code.
Recommendations For TN-5900 Series firmware versions v3.3 and prior, update to a version later than v3.3 to resolve the issue. As a temporary workaround, consider restricting access to the key-generation function until a patch is available. Additionally, ensure proper input validation and authentication mechanisms are in place to minimize the risk of exploitation.

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05028
CVE-2023-34213

Produtos afetados

Tn-5900 Series