PT-2023-4620 · Moxa · Moxa Tn-4900 Series+1
Published
2023-08-16
·
Updated
2024-10-28
·
CVE-2023-33239
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moxa TN-4900 Series firmware versions v1.2.4 and prior
Moxa TN-5900 Series firmware versions v3.3 and prior
Description
The issue stems from insufficient input validation in the key-generation function, which could potentially allow malicious users to execute remote code on affected devices. This is due to errors in processing input data in the key-generation function.
Recommendations
For Moxa TN-4900 Series firmware versions v1.2.4 and prior, update to a version later than v1.2.4 to resolve the issue.
For Moxa TN-5900 Series firmware versions v3.3 and prior, update to a version later than v3.3 to resolve the issue.
As a temporary workaround, consider restricting access to the key-generation function until a patch is available.
Fix
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moxa Tn-4900 Series
Moxa Tn-5900 Series