Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37406 | TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only high-privileged APIs are allowed This presents a potential risk of unauthorized exploitation by malicious actors. |
Solution
Moxa has developed appropriate solution to address the vulnerability. The solution for affected products is shown below: * TN-5900 Series: Please upgrade to firmware v3.4 or higher.
Workaround
No workaround given by the vendor.
Mon, 28 Oct 2024 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only high-privileged APIs are allowed This presents a potential risk of unauthorized exploitation by malicious actors. | TN-5900 Series firmware version v3.3 and prior is vulnerable to improper-authentication vulnerability. This vulnerability arises from inadequate authentication measures implemented in the web API handler, allowing low-privileged APIs to execute restricted actions that only high-privileged APIs are allowed This presents a potential risk of unauthorized exploitation by malicious actors. |
| Weaknesses | CWE-863 |
Tue, 08 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Moxa
Published:
Updated: 2024-10-28T06:01:08.088Z
Reserved: 2023-05-19T02:30:16.483Z
Link: CVE-2023-33237
Updated: 2024-08-02T15:39:35.732Z
Status : Modified
Published: 2023-08-17T02:15:41.177
Modified: 2024-11-21T08:05:12.713
Link: CVE-2023-33237
No data.
OpenCVE Enrichment
No data.
EUVD