TN-5900 Series prior to version 3.3 and the TN-4900 Series prior to version 1.2.4 are affected by multiple web server vulnerabilities. Insufficient input validation causes these vulnerabilities. An attacker could exploit the vulnerabilities by sending crafted input to the web service. If exploited successfully, these vulnerabilities could lead to Denial-of-Service, remote code execution, and privilege escalation.
The identified vulnerability types and potential impacts are shown below:
| Item | Vulnerability Type | Impact |
|---|---|---|
| 1 |
Improper Authentication (CWE-287) CVE-2023-33237 |
An attacker can use brute force to break the authentication parameters. |
| 2 |
Improper Neutralization of Special Elements used in a Command ('Command Injection') (CWE-77) CVE-2023-33238, CVE-2023-33239, CVE-2023-34213, CVE-2023-34214, CVE-2023-34215 |
An attacker located remotely can execute arbitrary commands on the device via a web interface. |
| 3 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) CVE-2023-34216, CVE-2023-34217 |
An attacker may be able to create or overwrite critical files that are used to execute code, such as programs or libraries. |
Vulnerability Scoring Details
| ID | CVSS v3.1 | Vector | Remote Exploit without Auth? |
|---|---|---|---|
| CVE-2023-33237 | 8.8 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-33238 | 7.2 | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-33239 | 8.8 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-34213 | 8.8 | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-34214 | 7.2 | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-34215 | 7.2 | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H | No |
| CVE-2023-34216 | 8.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H | No |
| CVE-2023-34217 | 8.1 | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H | No |
This alert has come from: https://www.moxa.com/en/support/product-support/security-advisory/mpsa-230402-tn-5900-and-tn-4900-series-web-server-multiple-vulnerabilities