CVE-2023-33235

MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:moxa:mxsecurity:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 08:05

Type Values Removed Values Added
References () https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities - Patch, Vendor Advisory () https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 7.2

30 May 2023, 19:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References (MISC) https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities - (MISC) https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities - Patch, Vendor Advisory
CPE cpe:2.3:a:moxa:mxsecurity:1.0:*:*:*:*:*:*:*
CWE CWE-77
First Time Moxa mxsecurity
Moxa

Information

Published : 2023-05-22 06:15

Updated : 2024-11-21 08:05


NVD link : CVE-2023-33235

Mitre link : CVE-2023-33235

CVE.ORG link : CVE-2023-33235


JSON object : View

Products Affected

moxa

  • mxsecurity
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')