PT-2023-4620 · Moxa · Moxa Tn-4900 Series+1

Published

2023-08-16

·

Updated

2024-10-28

·

CVE-2023-33239

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moxa TN-4900 Series firmware versions v1.2.4 and prior Moxa TN-5900 Series firmware versions v3.3 and prior
Description The issue stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices. This is due to errors in processing input data in the key-generation function.
Recommendations For Moxa TN-4900 Series firmware versions v1.2.4 and prior, update to a version later than v1.2.4 to resolve the issue. For Moxa TN-5900 Series firmware versions v3.3 and prior, update to a version later than v3.3 to resolve the issue. As a temporary workaround, consider restricting access to the key-generation function until a patch is available.

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-05027
CVE-2023-33239

Affected Products

Moxa Tn-4900 Series
Moxa Tn-5900 Series