PT-2023-4605 · Unknown · Tn-5900 Series

Published

2023-08-16

·

Updated

2024-10-28

·

CVE-2023-34215

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TN-5900 Series firmware versions prior to v3.3
Description The issue stems from insufficient input validation and improper authentication in the certification-generation function. This could potentially allow malicious users to execute remote code on affected devices. The vulnerability is related to errors in processing input data in the certification-generation function.
Recommendations For TN-5900 Series firmware versions prior to v3.3, update to a version later than v3.3 to resolve the issue. As a temporary workaround, consider restricting access to the certification-generation function until a patch is available. Avoid using the certification-generation function with untrusted input until the issue is resolved.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-05012
CVE-2023-34215

Affected Products

Tn-5900 Series