These vulnerabilities are caused by the improper design or implementation of authentication mechanisms and input validation. Exploiting these vulnerabilities could enable an attacker to bypass authentication, which could lead to the unauthorized disclosure or tampering of authenticated information, unauthorized access to sensitive data, and remote access without proper authorization.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Small Space of Random Values (CWE-334)
CVE-2023-39979
|
An attacker can bypass authentication to gain unauthorized access. |
| 2 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
CVE-2023-39980
|
An attacker can change the SQL command to gain unauthorized access to disclose information. |
| 3 |
Improper Authentication (CWE-287)
CVE-2023-39981
|
An attacker can gain unauthorized access to disclose device information. |
| 4 |
Use of Hard-coded Credentials (CWE-798)
CVE-2023-39982
|
An attacker can facilitate man-in-the-middle attacks and enable the decryption of SSH traffic. |
| 5 |
Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915)
CVE-2023-39983 |
An attacker can register/add a device via the nsm-web application. |
Vulnerability Scoring Details
| ID | CVSS V3.1 | VECTOR | REMOTE EXPLOIT WITHOUT AUTH? |
|---|---|---|---|
| CVE-2023-39979 | 9.8 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | Yes |
| CVE-2023-39980 | 7.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N | No |
| CVE-2023-39981 | 7.5 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | Yes |
| CVE-2023-39982 | 7.5 | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | Yes |
| CVE-2023-39983 | 5.3 | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N | Yes |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230403-mxsecurity-series-multiple-vulnerabilities