CVE-2023-33235 (ZDI-CAN-19895)
A vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
CVE-2023-33236 (ZDI-CAN-19896)
A vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Neutralization of Special Elements Used in a Command ('Command Injection') (CWE-77)
CVE-2023-33235 (ZDI-CAN-19895)
|
An attacker located remotely who has gained authorization privileges can execute arbitrary commands on the device.
|
| 2 |
Use of Hard-coded Credentials (CWE-798)
CVE-2023-33236 (ZDI-CAN-19896)
|
An attacker may be able to bypass authentication for web-based APIs.
|
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities