MXsecurity Command Injection and Hardcoded Credential Vulnerabilities

Published: May 29, 2023

This Alert Is From MOXA

As Industrial IoT (IIoT) adoption continues to proliferate, cybersecurity has become one of the top priorities. The Moxa Product Security Incident Response Team (PSIRT) takes a proactive approach to protect products from cybersecurity vulnerabilities. Moxa PSIRT investigates all reports of vulnerabilities that could potentially affect Moxa products. Moxa created a vulnerability management policy to provide guidance and information to our customers in the event of a reported vulnerability. The management policy ensures that Moxa’s customers have steady, unambiguous resources to help them understand how Moxa resolves or mitigates reported vulnerabilities. For any queries, please email [email protected].

CVE-2023-33235 (ZDI-CAN-19895)
A vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.

CVE-2023-33236 (ZDI-CAN-19896)
A vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

The identified vulnerability types and potential impacts are shown below:

Item Vulnerability Type Impact
1
Improper Neutralization of Special Elements Used in a Command ('Command Injection') (CWE-77)
CVE-2023-33235 (ZDI-CAN-19895)
An attacker located remotely who has gained authorization privileges can execute arbitrary commands on the device.
2
Use of Hard-coded Credentials (CWE-798)
CVE-2023-33236 (ZDI-CAN-19896)
An attacker may be able to bypass authentication for web-based APIs.

 

This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities